- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk UBA Anomalies and Threats
dania_abujuma
Engager
10-27-2024
01:20 AM
Hi everyone,
I have started working in Splunk UBA recently, and have some questions:
- Anomalies:
- How long does it take to identify anomalies after receiving the logs usually?
- Can I define anomaly rules?
- Is there anywhere to explain the existing anomaly categories are based on what or will be looking for what in the traffic?
- Threats:
- How long does it take to trigger threats after identifying anomalies?
- Is there any source I can rely on for creating threat rules? As I am creating rules and testing but with no results.
