Send notable events from Splunk Enterprise Security to Splunk UBA

You can send notable events from Splunk Enterprise Security (ES) to Splunk UBA to be processed for anomalies. You can use Splunk UBA to generate threats from the correlation search anomalies.

Note: For Splunk UBA version 5.4.0 and higher, the Splunk ES account being used for UBA-ES integration must have the edit_token_http capability.

For more information see How Splunk UBA sends and receives data from the Splunk platform in Send and Receive Data from the Splunk Platform.