All Apps and Add-ons

In Splunk UBA, ALL domains in anomalies are showing as IP addresses


For some reason all anomalies that use domain names (Suspicious HTTP Redirects, Suspicious Domain Communication, Blacklisted Domain) are only using the IP addresses of my traffic. All of these detections are using Splunk Stream. When I look at the anomalies, it has

"The following features increased the suspiciousness of the requests:

Domain name being an IP"

even though the actual Stream events have the domain names in them. Looking into the stream events it would seem that maybe they are being parsed incorrectly. There is a field listed called "" which lists the actual domain of the URL and then there is another called "stream.generic.uri_path" that has the rest of the URL. But it looks like UBA is putting the destination IP in the URL when it is correlating the event.

What this means is we cannot whitelist domains because UBA isn't even looking at the domains.

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...