As the title suggests, i am trying to onboard multiple data sources in Splunk UBA. I would like to see if there is a way i can see from the CLI on the EPS per each data source ingested.
The EPS fluctuates when we run data sources to ingest data from Specific time window even if the data exists within Splunk Enterprise as compared to AllTime.
So after much thought and deliberation, this is how you can see the real-time EPS and the trends around it on UBA.
1. You would need to add the parameter ?system in the url right before the # values.
2. Once done, proceed to Manage -> Data Sources -> Select Data Source to reveal the real-time EPS and trends associated with it.
So after much thought and deliberation, this is how you can see the real-time EPS and the trends around it on UBA.
1. You would need to add the parameter ?system in the url right before the # values.
2. Once done, proceed to Manage -> Data Sources -> Select Data Source to reveal the real-time EPS and trends associated with it.