Splunk User Behavior Analytics

How to list all possible values UBA can use for certain fields?

att35
Builder

Hi,

Is there a way to find out all values that UBA can understand for a certain field? e.g. Under Cloud Storge,
http://docs.splunk.com/Documentation/UBA/5.2.0/GetDataIn/CIMtoUBAfields#Cloud_Storage_category

For change_type, example column lists following.

Download, Preview, Delete, Create, Edit

Could there be others, e.g. Upload? There are other fields where the example set seems very limited.

I believe we can add additional values under 

/etc/caspida/local/conf/normalize.rules

but how do we ensure that UBA does understand those?

Thanks,

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...