Send data from Splunk Enterprise directly to Kafka
When working with large data sets, you can send events from Splunk Enterprise directly to Kafka for ingestion.
See Send data from Splunk Enterprise directly to Kafka in the Splunk UBA Kafka Ingestion App manual.
Add custom data to Splunk UBA using the generic data source | Splunk UBA category to Splunk CIM field mapping reference |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.0
Feedback submitted, thanks!