View UEBA dashboards

Access the UEBA Overview, User Analysis, and Asset Analysis dashboards to monitor and analyze user and entity behavior.

Use these steps to access and explore the UEBA dashboards. For important details on dashboards, including the Overview dashboard, see Understanding the UEBA Dashboards.

  1. Navigate to the UEBA overview dashboard.
    Select Analytics and then UEBA.
    1. Enter a user or asset name in the search bar.
    2. Wait for data to populate.
      Risk calculations and lookups can take up to 30 minutes to appear.
    3. If the dashboard remains empty after one hour, check for findings in index=risk.
    4. Contact Splunk Support if the dashboard still has no data.
  2. Open the user or asset analysis dashboards.
    Select Analytics and then UEBA.
    1. Enter a user or asset name in the search bar.
    2. Select a result to view detailed behavioral and contextual information.