Splunk UBA 的各种配置生效,都离不开参数的发挥作用,下面就列一下Splunk UBA 在配置文件中: /etc/caspida/local/conf/confuba-site.properties 的各种参数:
Manage Splunk UBA configuration properties in the uba-site.properties file
Configure Splunk UBA by adding or editing properties in the /etc/caspida/local/conf/uba-site.properties
file. Customizations made in this file are not modified during any upgrade procedures.
1: Splunk UBA environment properties
2: Splunk UBA and Splunk Enterprise Security (ES) properties
3: Event drilldown properties
4: Raw event data ingestion properties
5: Asset and identity data ingestion properties
6: Kafka data i