Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Splunk User Behavior Analytics (Splunk UBA)
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Splunk User Behavior Analytics (Splunk UBA)

Overview
Details
Splunk UBA is a machine learning driven solution that helps organizations find hidden threats and anomalous behavior across users, devices, and applications. Its data science driven approach produces actionable results with risk ratings and supporting evidence, augmenting SOC analysts’ existing techniques. In addition, it provides visual pivot points for hunters to proactively investigate anomalous behavior.

• Detects insider threats using out-of-the-box purpose-built but extensible unsupervised machine learning (ML) algorithms
• Provides context around the threat via ML driven anomaly correlation and visual mapping of stitched anomalies over various phases of the attack lifecycle (Kill Chain View)
• Increases SOC efficiency with rank-ordered threats and supporting evidence
• Supports bi-directional integration with Splunk Enterprise for data ingestion and correlation and with Splunk Enterprise Security for incident scoping, workflow management and automated response

Splunk User Behavior Analytics (UBA) is built on a big data platform (Hadoop) that horizontally scales and analyzes behavior of hundreds-of-thousands of users, devices and applications. It process data generated from various technologies: network, endpoint, identity, cloud, and applications, to identify anomalous behavior, and stitch applicable anomalies into threat(s) using its multi-pass machine learning architecture.

Splunk UBA visualizes the threat over a kill-chain, thereby, providing contextual awareness, along with supporting evidence for SOC analyst to consume.

Splunk UBA provides organizations the ability to:

• Enhance detection footprint by using behavior centric approach
• Augment SOC analyst by automatically stitching hundreds of anomalies into a single threat
• Provide enhanced context by visualizing the threat across multiple phases of an attack

For more information see the Splunk UBA Home Page and Splunk User Behavior Analytics Documentation
https://www.splunk.com/en_us/products/premium-solutions/user-behavior-analytics.html
http://docs.splunk.com/Documentation/UBA

Splunk Certification Program

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2017 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.