Splunk Enterprise Security

Clarification on UBA Capability in Splunk Enterprise Security vs MLTK and RBA

tuongpx
New Member

Hello Splunk Community,

I would like to request clarification regarding Splunk Enterprise Security (ES) capabilities in relation to User Behavior Analytics (UBA).
In a current SIEM/SOC solution evaluation, one of the key requirements specifies that:
“The system must have the capability of User Behavior Analytics (UBA) to monitor and detect internal risks.”
A vendor has proposed using Splunk Enterprise Security (ES) with Machine Learning Toolkit (MLTK) and Risk-Based Alerting (RBA), stating that these features are equivalent to and can replace User Behavior Analytics (UBA) for managing user behavior and detecting insider threats.
I would appreciate clarification on the following points:
Does Splunk Enterprise Security (ES) natively include User Behavior Analytics (UBA) capabilities?
Can MLTK and RBA in Splunk ES be considered equivalent to, or a replacement for, Splunk UBA in terms of user behavior analysis and insider risk detection?
If not, is Splunk UBA a separate module required to provide these capabilities?
This clarification will help ensure a correct understanding of Splunk’s technical capabilities and licensing structure.
Thank you in advance for your insights and confirmation.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...