Splunk® User Behavior Analytics Monitoring App

Splunk UBA Monitoring App

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® User Behavior Analytics Monitoring App. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Enable Splunk UBA to forward data to Splunk Enterprise

After installing the Splunk UBA Monitoring app on the Splunk Enterprise search head, configure Splunk UBA to forward data to the Splunk platform.

Before you continue, make sure Splunk UBA is fully and properly installed or upgraded.

Perform the following steps to enable Splunk UBA to forward data to Splunk Enterprise. All steps are performed on the management node only:

  1. If Splunk UBA is running, use the following command to stop Splunk UBA:
    /opt/caspida/bin/Caspida stop
  2. Add the following properties to /etc/caspida/local/conf/uba-site.properties:
    splunk.forwarder.enabled=true
    splunk.forwarder.server.indexers=<splunk-host-to-forward-to>
    

    If the port number is not the default port of 9997, specify the port number with the name of the host as follows:

    splunk.forwarder.server.indexers=host1:9998

    Use commas to separate multiple hosts. For example, to configure the forwarder to load balance across a three-node Splunk indexer cluster, specify the following:

    splunk.forwarder.server.indexers=host1:9998,host2:9998,host3:9998
  3. In distributed deployments, synchronize the cluster to push configuration changes to all nodes:
    /opt/caspida/bin/Caspida sync-cluster /etc/caspida/local/conf
  4. Start Splunk UBA.
    /opt/caspida/bin/Caspida start
  5. Start the Splunk forwarder.
    /opt/caspida/bin/Caspida setup-splunk-forwarder
Last modified on 17 April, 2021
PREVIOUS
Install the Splunk UBA Monitoring App
  NEXT
Send all logs to Splunk Enterprise

This documentation applies to the following versions of Splunk® User Behavior Analytics Monitoring App: 1.0.0, 1.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters