Configure asset and identity data for UEBA in Splunk Enterprise Security

UEBA uses the Asset and Identity Framework in Splunk Enterprise Security to link intermediate findings to the correct user or asset and to enrich the intermediate findings with attributes of that user or asset. Asset and identity data powers entity lists, enriches intermediate findings with context, and ensures that risk scores are calculated for the right entities.

Before using UEBA, you must do the following:

The following fields from the Asset and Identity framework are used to normalize risk objects, support peer grouping, and provide relevant contextual information on the UEBA and entity pages.

Identity fields:
  • first, last
  • Email
  • identity
  • managedBy
  • bunit
  • StartDate
  • EndDate
  • Category
Asset fields:
  • asset
  • asset_tag
  • bunit
  • category
  • city
  • country
  • dns
  • ip
  • Mac
  • nt_host
  • owner
  • pci_domain
  • priority
Note: The UEBA diagnostics dashboard displays errors if asset and identity data is missing. See Auditing UEBA with the diagnostics dashboard.
For more information on the Asset and Identity framework, see Add asset and identity data to Splunk Enterprise Security.