Splunk User Behavior Analytics (UBA) 5.4 Delivers FIPS Compliance and Advanced Anomaly Detection

Splunk’s latest User Behavior Analytics (UBA) product update, version 5.4.0, brings enhancements and new features designed to streamline operations and improve threat detection accuracy. Let’s see what’s new!

Achieving New Standards with FIPS Compliance

With version 5.4.0, Splunk UBA now meets compliance requirements for Federal Information Processing Standards (FIPS), ensuring that data handling and encryption processes adhere to rigorous federal guidelines. This milestone underscores Splunk’s dedication to security and compliance, and expands the potential for government, public sector, and regulated industry customers to leverage Splunk UBA in their security operations.

Enhanced Integration with Splunk Enterprise Security for Risk-Based Alerting

Splunk UBA is now more closely integrated with Splunk Enterprise Security (ES) through the Risk-Based Alerting (RBA) framework and feature set. “But wait… what is RBA?” you ask? RBA uses the existing Splunk Enterprise Security correlation rule framework to collect interesting and potentially risky events into a single index with a shared language, which is then used for alerting. Events collected in the Risk Index produce a single “risk notable” only when certain criteria warranting an investigation are met. This increases security visibility, closes gaps, and reduces the volume of low fidelity alerts. This process transforms traditional alerts into potentially interesting observations which correlate into a high-fidelity security story for analysts to investigate.

In Splunk UBA 5.4, users can create and forward risk events from UBA-detected anomalies and threats directly to Splunk Enterprise Security. This integration ensures that organizations can maintain a more holistic view of their security posture, streamline responses, and enable more dynamic risk management.

Innovations in Anomaly Detection with the False Positive Suppression Model

Addressing one of the most challenging aspects of threat detection, the new False Positive Suppression Model significantly reduces the noise of false alerts. Utilizing advanced self-supervised deep learning algorithms, this offline batch model learns from user-tagged false positives to enhance its detection capabilities. By automatically identifying and tagging similar future anomalies, the model helps security teams focus on genuine threats without overlooking potential risks. This model exemplifies how machine learning can transform anomaly detection, providing a smarter, user-friendly way to manage alerts.

Detecting Anomalies in File Access with Precision

The newly introduced model for detecting unusual volumes of file access events per user will help users refine their data analysis. This model identifies outliers in the daily counts of file-related events per user, enhancing the ability to spot potential data exfiltration or unauthorized access activities within vast datasets.

Scalability and Performance Enhancements

The scalability and performance of the Account and Device Exfiltration models in Splunk UBA have seen significant improvements in Splunk UBA version 5.4:

These improvements ensure that Splunk UBA operates more efficiently, providing rapid, reliable analytics to help security teams act quickly.

Upgrade to Splunk UBA 5.4 Today

Splunk UBA 5.4.0 is now available, offering organizations the tools to detect insider threats and cyber attacks more effectively than ever. As cyber threats evolve, so do our solutions. Splunk UBA 5.4 is part of our ongoing commitment to deliver solutions that protect our customers in an ever-changing digital landscape.

To learn more about Splunk UBA, we encourage you to visit the product webpage, take a tour, and review our latest Splunk UBA 5.4 documentation.

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.