Splunk UBA 數(shù)據(jù)導(dǎo)入中可以接受的告警
像Splunk UBA 的數(shù)據(jù)導(dǎo)入過程中,就怕報錯,因為這個就是很多數(shù)據(jù)不能被UBA接收的原因。
像有些錯誤,就可以先ignore, 在Test mode 中報錯,沒有關(guān)系:
Confirm that the data source you added is successfully parsing events.
In Splunk UBA, select Manage >Data Sources.
Click the name of the data source that you added.
Review the Data Source Details.
Click the parsed events icon ( / ) and review the 10 sample events. Make sure that each event lists event views
There are times when some data sources, such as DHCP, DNS, AD, or HTTP do not provide a destination device. If you ingest one of these data types and see validation error messages, you can ignore these messages once you examine the raw event and validate the absence of the destination device in the raw event.
注意: 上面提到
你是否還在尋找穩(wěn)定的海外服務(wù)器提供商?創(chuàng)新互聯(lián)www.cdcxhl.cn海外機房具備T級流量清洗系統(tǒng)配攻擊溯源,準(zhǔn)確流量調(diào)度確保服務(wù)器高可用性,企業(yè)級服務(wù)器適合批量采購,新人活動首月15元起,快前往官網(wǎng)查看詳情吧