Splunk User Behavior Analytics

Exclude audio/video ips for excessive data transmission/ Data exfiltration in UBA

Prad_10
New Member

tried to add all ip's (basically audio/video streaming sites) in IP whitelist in UBA for excluding uba alert for excessive data transmission/ data exfiltration. However still UBA alerts are getting generated for those ip.
How to tune those alerts in uba.
Also noticed that those waitlisted ips is populated in devices field. Someone can please advise on thisScreenshot 2023-08-17 124017.png

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...