Upgrade Splunk UBA prerequisites
Splunk UBA 5.0 requires the Splunk UBA 4.3.1 platform release. See How to install or upgrade to Splunk UBA 5.0 for upgrade path information.
Before upgrade, perform the following tasks:
- This release provides support for multiple IP and MAC addresses during asset data ingestion provided that the addresses are separated by commas. If you have assets with multiple IP or MAC addresses using a different delimiter, set the
attribution.keyvalue.delimiter
property in/etc/caspida/local/conf/uba-site.properties
before upgrading Splunk UBA. See Configure asset ingestion for multi-valued fields for instructions. - In RHEL Linux environments, ensure that Splunk UBA has access to RHEL repositories.
- In RHEL Linux environments, review the External dependencies affected by this upgrade.
- Review the Known issues for this release.
- Verify that you have enough free space in
/home/caspida
to store the downloaded the extracted installer files. - Backup your system. See Prepare to backup Splunk UBA.
- Make sure your system is running normally by using the
uba_pre_check.sh
shell script.See Check system status before and after installation for more information about the script./opt/caspida/bin/utils/uba_pre_check.sh
After satisfying the prerequisite requirements, go to one of the following:
Secure the default account after installing Splunk UBA | Upgrade a single node AMI or OVA installation of Splunk UBA |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.0
Feedback submitted, thanks!