UBA : Large Outbound Transfer by High Risk User

The QRadar® User Behavior Analytics (UBA) app supports use cases based on rules for certain behavioral anomalies.

UBA : Large Outbound Transfer by High Risk User

Enabled by default

False

Default senseValue

15

Description

Detects an outbound transfer of 200,000 bytes or more by a high risk user.

Support rules

BB:UBA : Common Event Filters

Log source types

Log sources that have the CEP Bytes Sent defined.