Splunk UBA 数据导入中可以接受的告警
像Splunk UBA 的数据导入过程中,就怕报错,因为这个就是很多数据不能被UBA接收的原因。
像有些错误,就可以先ignore, 在Test mode 中报错,没有关系:
Verify that you successfully added the data source
Confirm that the data source you added is successfully parsing events.
-
In Splunk UBA, select Manage > Data Sources.
-
Click the name of the data source that you added.
-
Review the Data Source Details.
-
Click the parsed events icon ( / ) and review the 10 sample events. Make sure that each event lists event views
There are times when some data sources, such as DHCP, DNS, AD, or HTTP do not provide a destination device. If you ingest one of these data types and see validation error messages, you can ignore these messages once you examine the raw event and validate the absence of the destination device in the raw event.
注意: 上面提