Skip to content

Commit

Permalink
Update uba-lite_with_statistics.md
Browse files Browse the repository at this point in the history
mention of Splunk App for Behavioral Profiling, which is amazing
  • Loading branch information
7thdrxn authored Sep 12, 2024
1 parent e708eea commit 8676db2
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/searches/uba-lite_with_statistics.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# UBA-lite with Basic Statistics

By comparing entity activity against itself or entities in a peer group (IE business unit, asset category, etc), you can create rules that offer anomaly detection capabilities similar to a UBA/UEBA solution. In RBA, you might use this as rules that generate risk events, or a field to use as a risk factor, or even just tags for the entity so that when you're investigating a risk-based alert you have an idea that this entity has been behaving erratically compared to various standards of behavior.
By comparing entity activity against itself or entities in a peer group (IE business unit, asset category, etc), you can create rules that offer anomaly detection capabilities similar to a UBA/UEBA solution. In RBA, you might use this as rules that generate risk events, or a field to use as a risk factor, or even just tags for the entity so that when you're investigating a risk-based alert you have an idea that this entity has been behaving erratically compared to various standards of behavior. Also please consider using the incredible step-by-step guided mode of the [Splunk App for Behavioral Profiling](https://splunkbase.splunk.com/app/6980) by Josh Cowling, Rupert Truman, and Premkumar Vyas; it's incredible!

## Example: Event Count Variance per Category by Risk Object

Expand Down

0 comments on commit 8676db2

Please sign in to comment.