Settings

In Settings, you can select the repositories of the Logpoint Search Head and Distributed Logpoints for UEBA analysis. You can also enable the history service to forward 30 days of historical data to UEBA. If you do not enable the history service, Logpoint forwards input data from the date you configure the repos.

../_images/UEBA_Board_Settings_Enable_History.png

Settings

Selecting Repos and Enabling the History Service

You can select multiple repos from the drop-down list in Select Repos. The repos in the Repo Selector are grouped either by Distributed Logpoints (DLP) or by Repo.

  1. Go to Settings >> Configuration >> UEBA Board.

  2. Select the Settings tab.

  3. In Select Repos, click Change from the dropdown. From Repo Selector, choose to change how to group the repos.

../_images/UEBA_Board_Settings_Change_Repo.png

Selecting Repos

  1. Click Fetch Remote to fetch the repos of all the connected DLPs.

../_images/UEBA_Board_Settings_Fetch_Repo.png

Fetching Repos

  1. Click Reload.

  2. Select All repos from all Logpoints to select all the repos from all the connected Logpoints. If you select All repos from all Logpoints and add a new DLP in the Search Head, all the existing repos, as well as the newly added repos of the new DLP machine are also selected in the Search Head.

../_images/UEBA_Board_Settings_All_Repo.png

Selecting All Repos from all Logpoints

  1. Use the search field at the top right to find the relevant repos.

../_images/UEBA_Board_Settings_Search_Repo.png

Searching for Repos

  1. Click Done.

  2. Select Enable history service if you have 30 days of enriched and normalized input data. Enable the history service for better baseline and result. You can enable the history service only once.

    ../_images/UEBA_Board_Settings_Enable_History.png

    Enabling the History Service

  3. Click Update Repos. Logpoint performs a quick configuration check.

../_images/UEBA_Board_Settings_Update_Repos.png

Updating Repos

Defining the Risk Score to Prepare Anomalies for Alerts

UEBA anomalies with a risk score of 75 or greater are used in Alert Rules, by default. If you need to change the risk score:

  1. Go to Settings >> Configuration >> UEBA Board.

  2. Select the Settings.

  3. In Alert Logs Configuration, click Edit.

  4. Move the slider left or right to decrease or increase the risk score number.

../_images/UEBA_Board_Settings_Change_RiskScore.png

Changing the Risk Score

  1. Click Save.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support