Splunk® User Behavior Analytics Monitoring App

Splunk UBA Monitoring App

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® User Behavior Analytics Monitoring App. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Splunk UBA Monitoring app requirements

Review and validate the requirements before using the Splunk UBA Monitoring app.

Splunk UBA and Splunk Enterprise compatibility

The Splunk UBA Monitoring app requires the following combination of Splunk UBA with Splunk Enterprise:

Splunk UBA Version Splunk Enterprise Version
Splunk UBA 4.3.0 and later Splunk Enterprise 7.0 or later

The Splunk UBA Monitoring app is not supported on Splunk Cloud.

Configure where the Splunk UBA Monitoring app sends data

By default, the Splunk UBA Monitoring app forwards data to the _internal index on Splunk Enterprise. Users of the Splunk UBA Monitoring app must have read access to the _internal index in order to see any data when using the app. Users with the admin role have this permission by default. Non-admin users can be granted this access by qualified admin users. See About users and roles in the Splunk Enterprise Admin Manual.

Splunk UBA release 5.0.0 and later provide the option to send data to Splunk Enterprise using sourcetype uba:* instead of _internal. You must contact your Splunk support representative to obtain a new Splunk license for ingesting Splunk UBA logs free of charge. See Obtain a Splunk license for ingesting Splunk UBA logs in Install and Upgrade Splunk User Behavior Analytics.

Enable the receiver in Splunk Enterprise

The forwarder on Splunk UBA connects to the Splunk Enterprise receiver on port 9997 by default. The receiver on Splunk Enterprise must be enabled to receive data from the forwarder on Splunk UBA. See Enable a receiver in the Splunk Enterprise Forwarding Data manual.

Last modified on 25 October, 2019
PREVIOUS
About the Splunk UBA Monitoring app
  NEXT
Install the Splunk UBA Monitoring App

This documentation applies to the following versions of Splunk® User Behavior Analytics Monitoring App: 1.0.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters