Splunk Enterprise

Splunk UBA Anomalies and Threats

dania_abujuma
Engager

Hi everyone,

I have started working in Splunk UBA recently, and have some questions:

  1. Anomalies:
    • How long does it take to identify anomalies after receiving the logs usually?
    • Can I define anomaly rules?
    • Is there anywhere to explain the existing anomaly categories are based on what or will be looking for what in the traffic?
  2. Threats:
    • How long does it take to trigger threats after identifying anomalies?
    • Is there any source I can rely on for creating threat rules? As I am creating rules and testing but with no results.
Labels (3)
0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...