Turn on or turn off behavior-based detections in the risk or test index
ba_test. - In Splunk Enterprise Security, select Security content and then select Content management.
- To filter for behavior-based detections, change the Type filter to Behavior-based detection .
- Select the link for the detection that you want to turn on or turn off.
- To turn on a detection, select Turn on in risk index or Turn on in test index for the index you want to generate findings in.
- To turn off a detection so that it doesn't create findings in any index, select Off.