Send data from the Splunk platform directly to Kafka
When working with large data sets, you can send events from the Splunk platform directly to Kafka for ingestion.
See Send data from the Splunk platform directly to Kafka in the Splunk UBA Kafka Ingestion App manual.
Add custom data to Splunk UBA using the generic data source | Splunk UBA category to Splunk CIM field mapping reference |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.4.1, 5.0.5, 5.0.5.1, 5.1.0, 5.1.0.1, 5.2.0, 5.2.1, 5.3.0, 5.4.0, 5.4.1
Feedback submitted, thanks!