Splunk User Behavior Analytics

Anomaly action rule not applied to anomalies

snisaxena
Loves-to-Learn

Hi,

I have created a watchlist, AWS_IPs and added IP addresses to it. Further, I have created anomaly action rule to reduce the anomaly score by 3 and added AWS_IPs watchlist to it.
But I do not see this AAR getting applied to anomalies that have IP address which are listed in watchlist.

Can anyone please suggest what could the reason behind it and how can I resolve it.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...