Splunk User Behavior Analytics

EventHasNoEntities

ehsanafter
New Member

Hey guys
im trying to ingest haproxy logs in splunk uba.
now my issue is that im getting eventHasNoEntities for all events even tho they are parsed.
what does this error mean exactly?
does it mean it has no device or user associated with it?
or its missing some fields.
my main event key includes the whole haproxy logs

Labels (1)
0 Karma

jessieb_83
Path Finder

Any luck with this? 

I'm hitting the same.  Far as I can tell it's a generic way to say that UBA is missing some key point of data, but I can't tell which thing it's looking for. 

0 Karma

PrewinThomas
Motivator

@jessieb_83 

Before adding event data to your UBA, make sure you have already integrated your HR, Asset, and Identity data. The error eventHasNoEntities occurs when your data lacks entity-related CIM-compliant fields or values. Ensure that,

Your UBA contains Asset and Identity data before importing any event data.

Your event data is CIM-compliant and includes the necessary entity data fields.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

jessieb_83
Path Finder

Thanks for the input! I have Assets/Identities populated, I suspect my issue is CIM. 

Only issue is I'm not clear exactly what field is missing. 

0 Karma

PrewinThomas
Motivator

@jessieb_83 

Do your proxy log events include fields that identify a user or a device (such as src, dest, src_ip, dest_ip, host ...)?
Typically, proxy logs should be mapped to the Web data model. Check that your logs contain the necessary fields for proper mapping.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...