Splunk User Behavior Analytics (UBA) uses unsupervised machine learning to establish behavioral baselines for users and entities, then detects anomalies that deviate from those baselines. Unlike rule-based detection (which requires knowing what to look for), UBA surfaces unknown threats — the insider threat who gradually exfiltrates data over months, the compromised account performing unusual access patterns, or the service account suddenly running interactive logons.
UBA integrates directly with Splunk ES. Anomaly findings from UBA appear as threats in ES's Threat Activity framework, contributing risk scores to the RBA Risk Index. The architect designs the UBA → ES integration: which UBA threat categories map to which risk scores, and which UBA anomalies warrant immediate Notable Events vs. passive risk accumulation.
The architect configures UBA's data sources, model training windows, and anomaly threshold sensitivity. Too sensitive → alert fatigue from false positives on normal behavioral variation. Too loose → missed insider threats. Calibration is an ongoing operational process. Key UBA use cases: insider threat (data theft, privilege abuse), compromised account detection (credential stuffing, lateral movement), and external attack chain reconstruction.