The Data Privacy Module lets you encrypt entities in UEBA and directly explore encrypted raw events using the Explore Raw Events option.
Go to Settings >> System >> System Settings.
Select the Data Privacy Module tab.
Enable Data Privacy Module.
Select an Encryption Scheme.
Enter the Fields you want to encrypt and click Add. If you want to encrypt the user, website, share, server, resource, ip, or machine fields, you must also add the following fields:
userPrincipalName
sAMAccountName
entityName
alert
searchQuery
templates_info
share_path
object_name
host
domain
source_address
destination_address
source_machine_id
destination_machine_id
sender
SI_USER
Click Save.
While exploring raw events, the lookup process command does not enrich risk scores in the raw events.
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support