Manage UEBA entity lists
- In Splunk Enterprise Security, select Configure then All configurations.
- In the UEBA section, select Entity lists.
- View all existing UEBA entity lists.For each entity list, you can find configuration values, audit fields, and the number of entities currently matching its criteria.
- To modify an existing entity list, select the pencil icon under the Actions column.Note: You can't change the entity list name.
- To delete an entity list, select the trash icon (
) in the Actions column. Deleting a list does not affect the underlying Assets & Identities Framework data.