I would also suggest you to get in touch with your Splunk account manager and the sales engineer. They will help you to do the POC of UEBA properly with use cases and help you to buy it as well, should you choose to go with it.
Hope this helps,
***If this helped, please accept it as a solution. It helps others to find the solution for similar issues quickly.***
Thank you, Shiv ###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###