Microsoft Sentinel now attaches User and Entity Behavior Analytics (UEBA) insights to records from the UEBA behaviors layer. UEBA is a machine-learning feature that builds a baseline of typical activity for users, hosts, IP addresses, and applications, then flags activity that does not match that baseline. The behaviors layer groups raw security logs into structured summaries of who did what to whom. Microsoft added those findings to each behavior and expanded UEBA coverage to selected firewall, proxy, and cloud sources. The anomalies-on-behaviors capability is in preview and is available only for Microsoft Sentinel in the Microsoft Defender portal.
Source