Splunk® User Behavior Analytics

Install and Upgrade Splunk User Behavior Analytics

This documentation does not apply to the most recent version of Splunk® User Behavior Analytics. For documentation on the most recent version, go to the latest release.

Upgrade Splunk UBA prerequisites

Splunk UBA 5.0.4 requires any previous Splunk UBA 5.0.x release. See How to install or upgrade to this release of Splunk UBA for upgrade path information.

Before you upgrade, perform the following tasks:

  1. In RHEL Linux environments:
    • Ensure that Splunk UBA has access to RHEL repositories.
    • Review the External dependencies affected by this upgrade in the Release Notes.
  2. Review the Known issues for this release in the Release Notes.
  3. The software update contains archive files approximately 50KB, 300MB, and 500MB in size. The total extracted size is approximately 1GB. Verify that you have enough free space in /home/caspida to store the downloaded the extracted installer files.
  4. Backup your system.
  5. If you are using the Splunk UBA Monitoring app, upgrade to version 1.1. See About The Splunk UBA Monitoring app in the Splunk User Behavior Analytics Monitoring App manual.
  6. Make sure your system is running normally by using the uba_pre_check.sh shell script.
    /opt/caspida/bin/utils/uba_pre_check.sh
    See Check system status before and after installation for more information about the script.

After satisfying the prerequisite requirements, go to one of the following:

Last modified on 15 March, 2021
Secure the default account after installing Splunk UBA   Upgrade a single node AMI or OVA installation of Splunk UBA

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.4


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters