Splunk® Add-on for Splunk UBA

Splunk Add-on for Splunk UBA

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Add-on for Splunk UBA. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Deploy the Splunk add-on for Splunk UBA

Determine where and how to install this add-on in your distributed deployment using the tables on this page.

Depending on your environment, your preferences, and the requirements of the add-on, you might need to install the add-on in multiple places.

To deploy it alongside Splunk Enterprise Security, see Deploy add-ons included with Splunk Enterprise Security in the Splunk Enterprise Security Installation and Configuration Manual.

Where to install this add-on

Splunk instance type Supported Required Comments
Search Heads Yes Yes This add-on is installed on the search head when you install Enterprise Security.
Indexers Yes Yes This add-on includes two indexes and index-time configurations.
Heavy Forwarders Yes No. All forwarder types are supported. Installing on a forwarder is not required.
Universal Forwarders Yes No. All forwarder types are supported. Installing on a forwarder is not required.
Light Forwarders Yes No. All forwarder types are supported. Installing on a forwarder is not required.

Distributed deployment feature compatibility

This table describes the compatibility of this add-on with Splunk distributed deployment features.

Distributed deployment feature Supported Details
Search Head Clusters Yes Changes made during setup must be manually deployed.
Indexer Clusters Yes This add-on contains indexes.
Deployment Server Yes Supported for deploying the configured add-on to multiple nodes.
Last modified on 12 April, 2024
PREVIOUS
Release notes for the Splunk add-on for Splunk UBA
  NEXT
Integrate Splunk Enterprise Security and Splunk UBA with this add-on

This documentation applies to the following versions of Splunk® Add-on for Splunk UBA: 3.0.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters