Additional resources for creating a correlation search

Defining your search

Search scheduling

For information on real-time and continuous search scheduling, see the Splunk platform documentation.

For information on search schedule priority, see the Splunk platform documentation.

Alerting conditions

For information on trigger conditions and configuring those conditions for a search, see the Splunk platform documentation.

Notable event details

For details about how to make sure that additional fields appear in the notable event details, see Change notable event fields in Administer Splunk Enterprise Security.