Configure asset and identity data for UEBA in Splunk Enterprise Security

UEBA uses the Asset and Identity Framework in Splunk Enterprise Security to link intermediate findings to the correct user or asset and to enrich the intermediate findings with attributes of that user or asset. Asset and identity data powers entity lists, enriches intermediate findings with context, and ensures that risk scores are calculated for the right entities.

Before using UEBA, you must do the following:
Note: The UEBA diagnostics dashboard displays errors if asset and identity data is missing. See Auditing UEBA with the diagnostics dashboard.
For more information on the Asset and Identity Framework, see Add asset and identity data to Splunk Enterprise Security.