Hi,
Is there a way to find out all values that UBA can understand for a certain field? e.g. Under Cloud Storge,
http://docs.splunk.com/Documentation/UBA/5.2.0/GetDataIn/CIMtoUBAfields#Cloud_Storage_category
For change_type, example column lists following.
Download, Preview, Delete, Create, Edit
Could there be others, e.g. Upload? There are other fields where the example set seems very limited.
I believe we can add additional values under
/etc/caspida/local/conf/normalize.rules
but how do we ensure that UBA does understand those?
Thanks,