tried to add all ip's (basically audio/video streaming sites) in IP whitelist in UBA for excluding uba alert for excessive data transmission/ data exfiltration. However still UBA alerts are getting generated for those ip.
How to tune those alerts in uba.
Also noticed that those waitlisted ips is populated in devices field. Someone can please advise on this