Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring | Splunk
As the demands of our customers continue to rise, Splunk User Behavior Analytics (UBA) V5.3 now boasts an increased ingesting rate up to 160K EPS from Splunk Enterprise to a 20-node large deployment. This scalability improvement facilitates support for 750K user accounts, 1 million devices, and 64 data sources[1]. Detecting anomalous user behaviors within a configurable 30-day timeframe, at such a scale of data volume from cybersecurity, poses significant performance challenges when building AI/ML-driven detection models. One of our guiding principles for evolving Splunk UBA is to enhance the scalability of detection models and help customers address many operational issues that are linked to large scales. We will be presenting a series of blogs on this topic to support more UBA customers in scaling up their Splunk user behavior analytics. As the first blog from this series, we will first introduce some fundamental techniques to validate data volume and monitor models to understand the
Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring | Splunk Building Large-Scale User Behavior Analytics: Data Validation and Model Monitoring Security February 12, 2024 Cui Lin As the demands of our customers continue to rise, Splunk User Behavior Analytics (UBA) V5.3 now boasts an increased ingesting rate up to 160K EPS from Splunk Enterprise to a 20-node large deployment. This scalability improvement facilitates support for 750K user accounts, 1 million devices, and 64 data sources [1] . Detecting anomalous user behaviors within a configurable 30-day timefram
related reading
- Building At-Scale User Behavior Analytics for Splunk UBA: Enhance Performance of Account & Device Exfiltration Models | Splunksplunk.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com
- Splunk User Behavior Analytics (UBA) 5.4 Delivers FIPS Compliance and Advanced Anomaly Detection | Splunksplunk.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Big Data is Deadmotherduck.com
- Boxer: Data Analytics on Network-enabled Serverless Platformsresearch-collection.ethz.ch
- Spotify’s official technology blog | Spotify Engineeringengineering.atspotify.com
- Go smol or go home | Harm de Vriesharmdevries.com
- Toward A Public Science of Model Behavior | Transluce AItransluce.org
- Unsupervised Machine Learning with Splunk: the cluster command | by Alex Teixeira | Detect FYIdetect.fyi
- Sundial: Opinionated Intelligence for data teamssundial.ai
- UEBA (User and Entity Behavior Analytics): Complete 2025 Guideexabeam.com