Filter by entity lists in UEBA dashboards

Use the UEBA dashboards to filter and explore entity lists for your investigation.
Create an entity list. See Add a new entity list.
  1. In Splunk Enterprise Security, select Analytics and then UEBA.
  2. To filter by an entity list in the UEBA overview dashboard, select one from the Entity list drop-down list.
    Note: You can also select Uncategorized to filter by entities that don't match any defined list
  3. (Optional) You can filter by more than one entity list. When you select multiple lists, the dashboard panels display data for entities present in any of the selected lists. For example, selecting "Known Users" and "Known Assets" shows data for entities in either list.