<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EventHasNoEntities in Splunk User Behavior Analytics</title>
    <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/749045#M78</link>
    <description>&lt;P&gt;Thanks for the input! I have Assets/Identities populated, I suspect my issue is CIM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only issue is I'm not clear exactly what field is missing.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jul 2025 14:46:16 GMT</pubDate>
    <dc:creator>jessieb_83</dc:creator>
    <dc:date>2025-07-01T14:46:16Z</dc:date>
    <item>
      <title>EventHasNoEntities</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/709765#M74</link>
      <description>&lt;P&gt;Hey guys&lt;BR /&gt;im trying to ingest haproxy logs in splunk uba.&lt;BR /&gt;now my issue is that im getting eventHasNoEntities for all events even tho they are parsed.&lt;BR /&gt;what does this error mean exactly?&lt;BR /&gt;does it mean it has no device or user associated with it?&lt;BR /&gt;or its missing some fields.&lt;BR /&gt;my main event key includes the whole haproxy logs&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 15:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/709765#M74</guid>
      <dc:creator>ehsanafter</dc:creator>
      <dc:date>2025-01-25T15:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: EventHasNoEntities</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/748975#M76</link>
      <description>&lt;P&gt;Any luck with this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm hitting the same.&amp;nbsp; Far as I can tell it's a generic way to say that UBA is missing some key point of data, but I can't tell which thing it's looking for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 19:55:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/748975#M76</guid>
      <dc:creator>jessieb_83</dc:creator>
      <dc:date>2025-06-30T19:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: EventHasNoEntities</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/748986#M77</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/215238"&gt;@jessieb_83&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before adding event data to your UBA, make sure you have already integrated your HR, Asset, and Identity data. The error eventHasNoEntities occurs when your data lacks entity-related CIM-compliant fields or values. Ensure that,&lt;/P&gt;&lt;P&gt;Your UBA contains Asset and Identity data before importing any event data.&lt;/P&gt;&lt;P&gt;Your event data is CIM-compliant and includes the necessary entity data fields.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 04:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/748986#M77</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-01T04:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: EventHasNoEntities</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/749045#M78</link>
      <description>&lt;P&gt;Thanks for the input! I have Assets/Identities populated, I suspect my issue is CIM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only issue is I'm not clear exactly what field is missing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 14:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/749045#M78</guid>
      <dc:creator>jessieb_83</dc:creator>
      <dc:date>2025-07-01T14:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: EventHasNoEntities</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/749074#M79</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/215238"&gt;@jessieb_83&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do your proxy log events include fields that identify a user or a device (such as src, dest, src_ip, dest_ip, host ...)?&lt;BR /&gt;Typically, proxy logs should be mapped to the Web data model. Check that your logs contain the necessary fields for proper mapping.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 04:32:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/EventHasNoEntities/m-p/749074#M79</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-02T04:32:03Z</dc:date>
    </item>
  </channel>
</rss>

