Hi everyone,
I have started working in Splunk UBA recently, and have some questions:
- Anomalies:
- How long does it take to identify anomalies after receiving the logs usually?
- Can I define anomaly rules?
- Is there anywhere to explain the existing anomaly categories are based on what or will be looking for what in the traffic?
- Threats:
- How long does it take to trigger threats after identifying anomalies?
- Is there any source I can rely on for creating threat rules? As I am creating rules and testing but with no results.