Splunk® User Behavior Analytics

Install and Upgrade Splunk User Behavior Analytics

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® User Behavior Analytics. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Upgrade Splunk UBA prerequisites

Splunk UBA 5.0.3 requires the Splunk UBA 5.0.1 maintenance release. See How to install or upgrade to this release of Splunk UBA for upgrade path information.

Splunk UBA release 5.0.3 on Linux operating systems is available in a patch installation package with the version number 5.0.3.1.

Splunk UBA 5.0.3 includes the following updated packages:

  • JVM version 1.8.0_242
  • An updated docker image centos7-splunkuba-deps

Before you upgrade, perform the following tasks:

  1. In RHEL Linux environments:
    1. Ensure that Splunk UBA has access to RHEL repositories.
    2. Review the External dependencies affected by this upgrade.
  2. Review the Known issues for this release.
  3. The software update contains two archive files approximately 300MB and 275MB in size. The total extracted size is approximately 1GB. Verify that you have enough free space in /home/caspida to store the downloaded the extracted installer files.
  4. Backup your system. See Prepare to backup Splunk UBA.
  5. If you are using the Splunk UBA Monitoring app, upgrade to version 1.1. See About The Splunk UBA Monitoring app.
  6. Make sure your system is running normally by using the uba_pre_check.sh shell script.
    /opt/caspida/bin/utils/uba_pre_check.sh
    See Check system status before and after installation for more information about the script.

After satisfying the prerequisite requirements, go to one of the following:

Last modified on 13 August, 2020
PREVIOUS
Secure the default account after installing Splunk UBA
  NEXT
Upgrade a single node AMI or OVA installation of Splunk UBA

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.3


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters