Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring | Splunk
As the demands of our customers continue to rise, Splunk User Behavior Analytics (UBA) V5.3 now boasts an increased ingesting rate up to 160K EPS from Splunk Enterprise to a 20-node large deployment. This scalability improvement facilitates support for 750K user accounts, 1 million devices, and 64 data sources[1]. Detecting anomalous user behaviors within a configurable 30-day timeframe, at such a scale of data volume from cybersecurity, poses significant performance challenges when building AI/ML-driven detection models. One of our guiding principles for evolving Splunk UBA is to enhance the scalability of detection models and help customers address many operational issues that are linked to large scales. We will be presenting a series of blogs on this topic to support more UBA customers in scaling up their Splunk user behavior analytics. As the first blog from this series, we will first introduce some fundamental techniques to validate data volume and monitor models to understand the
Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring | Splunk Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring Security February 12, 2024 Cui Lin As the demands of our customers continue to rise, Splunk User Behavior Analytics (UBA) V5.3 now boasts an increased ingesting rate up to 160K EPS from Splunk Enterprise to a 20-node large deployment. This scalability improvement facilitates support for 750K user accounts, 1 million devices, and 64 data sources [1] . Detecting anomalous user behaviors within a configurable 30-day timefram
Explore this link on the map →related reading
- Building At-Scale User Behavior Analytics for Splunk UBA: Enhance Performance of Account & Device Exfiltration Models | Splunksplunk.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com
- Splunk User Behavior Analytics (UBA) 5.4 Delivers FIPS Compliance and Advanced Anomaly Detection | Splunksplunk.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Boxer: Data Analytics on Network-enabled Serverless Platformsresearch-collection.ethz.ch
- Go smol or go home | Harm de Vriesharmdevries.com
- Unsupervised Machine Learning with Splunk: the cluster command | by Alex Teixeira | Detect FYIdetect.fyi
- Claude Statusstatus.claude.com
- UEBA (User and Entity Behavior Analytics): Complete 2025 Guideexabeam.com
- UEBA Superpowers: Enhance Security Visibility with Rich Insights to Take Rapid Action Against Threats | Splunksplunk.com
- GitHub - suzana-ilic/study_model_behavior: Model Behavior Study Group · GitHubgithub.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com