Edit anomaly scoring rules
Custom anomaly scoring is performed in the following ways:
- New anomalies created by cloning an existing model inherit the base score from the parent or source model.
- New anomalies created without cloning any existing models have a default base score of 6.
After new anomalies are created in Splunk UBA, you can edit the scoring rules for your custom anomalies. Admin privileges are required to edit anomaly scoring rules.
Perform the following tasks to customize the anomaly scoring rules for anomalies generated by your custom models:
- If you are logged in to Splunk UBA as a user with Content_Developer privileges, log out of Splunk UBA.
- Log in to Splunk UBA as a user with Admin privileges.
- To customize the scoring rules for the anomalies generated by your custom models, follow the instructions in Customize anomaly scoring rules in Administer Splunk User Behavior Analytics.
Edit or delete custom models | Example: Create a new custom badge access model |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.4.1, 5.0.5, 5.0.5.1, 5.1.0, 5.1.0.1, 5.2.0, 5.2.1, 5.3.0, 5.4.0, 5.4.1
Feedback submitted, thanks!