Configure asset and identity data for UEBA in Splunk Enterprise Security

UEBA uses the Asset and Identity Framework in Splunk Enterprise Security to link detections to the correct users and devices. Asset and identity data powers entity lists, enriches detections with context, and ensures that risk scores are calculated for the right entities.

Before using UEBA, you must do the following:
Note: The UEBA diagnostics dashboard displays errors if asset and identity data is missing. See Auditing UEBA with the diagnostics dashboard.
For more information on the Asset and Identity Framework, see Add asset and identity data to Splunk Enterprise Security.