Splunk® Add-on for Splunk UBA

Splunk Add-on for Splunk UBA

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Set up the Splunk add-on for Splunk UBA

Set up the Splunk add-on for Splunk UBA to send data to and retrieve data from Splunk UBA.

  • Send saved search results to Splunk UBA from the Splunk platform with an alert action.
  • Retrieve user and device association data from Splunk UBA.

The add-on includes a custom capability, edit_uba_settings that is added to the ess_admin role in Splunk Enterprise Security and can be assigned.

See Integrate Splunk Enterprise Security and Splunk UBA with this add-on for more on how to set up the Splunk add-on for Splunk UBA. If you set up the add-on without performing the additional integration steps, data cannot be correctly retrieved or sent.

Last modified on 05 March, 2020

This documentation applies to the following versions of Splunk® Add-on for Splunk UBA: 3.0.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters