- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to list all possible values UBA can use for certain fields?
att35
Builder
04-12-2023
04:43 AM
Hi,
Is there a way to find out all values that UBA can understand for a certain field? e.g. Under Cloud Storge,
http://docs.splunk.com/Documentation/UBA/5.2.0/GetDataIn/CIMtoUBAfields#Cloud_Storage_category
For change_type, example column lists following.
Download, Preview, Delete, Create, Edit
Could there be others, e.g. Upload? There are other fields where the example set seems very limited.
I believe we can add additional values under
/etc/caspida/local/conf/normalize.rules
but how do we ensure that UBA does understand those?
Thanks,
