See which entity lists an entity is in

Create an entity list. See Add a new entity list.
Determine which entity lists an entity is included in using the UEBA analysis dashboards.
  1. In Splunk Enterprise Security, select Analytics and then UEBA.
  2. Select a user or asset from the table to open the UEBA entity analysis dashboard.
  3. In the Entity details panel, find the Entity lists field.
    Note: If an entity is included in more than one entity list, you can see its additional lists by hovering over the + icon.