See which entity lists an entity is in

Create an entity list. See Add a new entity list.
Determine which entity lists an entity is included in using the UEBA analysis dashboards.
  1. In Splunk Enterprise Security, select Analytics then UEBA.
  2. Select either UEBA user analysis or UEBA asset analysis.
  3. In the User details or Asset details panel, find the Entity lists field.
    Note: If an entity is included in more than one entity list, you can see its additional lists by hovering over the + icon.