I use Splunk UBA 5.3.0 when I try to add data source with splunk direct, raw events it will be error "There was an error processing your request. It has been logged (ID ...)"
How to fix it?
Splunk Enterprise I use 9.0.0 (Splunk Enterprise and Splunk UBA are fresh install)
Thanks for help.