Thanks @sherma for such comprehensive guide! I still couldn't bring up my UBA again, so I finally restore from vm snapshot and installed UBA again. I wonder it's my new network address crashed with docker network interface, but I'm not 100% sure. For someone who hit the same problem, may refer to this guide as well. https://docs.splunk.com/Documentation/UBA/5.2.0/Admin/ChangeDockerIP
... View more
To access the "Closed by User" and "Closed by System" options, start by selecting the "Threat Status" filter. Once you've done that, these specific options will become visible for your selection.
... View more