UEBA Content App for On-premises

Overview of the UEBA Content App for On-premises

Prerequisites for using UEBA in Splunk Enterprise Security

Complete the following before using UEBA functionality in Splunk Enterprise Security:
Task Documentation
Verify compatibility. UEBA compatibility
Grant permissions to users who need UEBA access. Roles and knowledge objects in UEBA for Splunk Enterprise Security
Collect and extract data in the Asset and Identity Framework.

Configure asset and identity data for UEBA in Splunk Enterprise Security.

Configure risk-based alerting. Risk scoring in Splunk Enterprise Security
Verify sourcetypes required for UEBA. Required sourcetypes for UEBA detections