Set up the Splunk add-on for Splunk UBA
Set up the Splunk add-on for Splunk UBA to send data to and retrieve data from Splunk UBA.
- Send saved search results to Splunk UBA from the Splunk platform with an alert action.
- Retrieve user and device association data from Splunk UBA.
The add-on includes a custom capability,
edit_uba_settings that is added to the
ess_admin role in Splunk Enterprise Security and can be assigned.
See Integrate Splunk Enterprise Security and Splunk UBA with this add-on for more on how to set up the Splunk add-on for Splunk UBA. If you set up the add-on without performing the additional integration steps, data cannot be correctly retrieved or sent.
This documentation applies to the following versions of Splunk® Add-on for Splunk UBA: 3.0.0