Integrate Splunk ES and Splunk UBA with the Splunk Add-on for Splunk UBA
Use the Splunk Add-on for Splunk UBA to integrate Splunk Enterprise Security (ES) and Splunk User Behavior Analytics (UBA).
You can integrate Splunk UBA and Splunk ES to share the following types of data:
- Send Splunk UBA anomalies and threats to Splunk ES as notable events.
- Pull notable events from Splunk ES to Splunk UBA.
- Send Splunk UBA audit events to Splunk ES.
- Send Splunk UBA user and device association data to Splunk ES.
For more information, see Viewing data from Splunk UBA in Enterprise Security in Use Splunk Enterprise Security.