Splunk Enterprise

Splunk UBA Anomalies and Threats

dania_abujuma
Engager

Hi everyone,

I have started working in Splunk UBA recently, and have some questions:

  1. Anomalies:
    • How long does it take to identify anomalies after receiving the logs usually?
    • Can I define anomaly rules?
    • Is there anywhere to explain the existing anomaly categories are based on what or will be looking for what in the traffic?
  2. Threats:
    • How long does it take to trigger threats after identifying anomalies?
    • Is there any source I can rely on for creating threat rules? As I am creating rules and testing but with no results.
Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...