All Apps and Add-ons

Is CEF an available data source for Splunk User Behavior Analytics (UBA)?

New Member

Hello.
I'm lookin to buy Splunk UBA, but I can't find information about available data sources in Splunk UBA.
We have Arcsight ESM, but we don't have Slunk Enterprise.

So can we directly send CEF to Splunk UBA?

0 Karma

Splunk Employee
Splunk Employee

Here is some information: http://docs.splunk.com/Documentation/UBA/4.2.0/GetDataIn/AddData

Contacting Splunk Sales will also provide you with a lot of information. In short, yes it is possible to send CEF data to Splunk UBA. Splunk Sales can confirm this.

0 Karma