Splunk User Behavior Analytics

Anomaly action rule not applied to anomalies

snisaxena
Loves-to-Learn

Hi,

I have created a watchlist, AWS_IPs and added IP addresses to it. Further, I have created anomaly action rule to reduce the anomaly score by 3 and added AWS_IPs watchlist to it.
But I do not see this AAR getting applied to anomalies that have IP address which are listed in watchlist.

Can anyone please suggest what could the reason behind it and how can I resolve it.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...