Splunk® User Behavior Analytics

Administer Splunk User Behavior Analytics

How to handle your Splunk UBA web interface certificates during migration

When Splunk UBA is restored using the restore script, your Splunk UBA web interface certification configuration is copied to the target system, but not the actual certificates themselves.

The following table summarizes how you need to handle your Splunk UBA web interface certificates during the migration process.

Restore scenario How to restore your Splunk UBA web interface certificates
Restoring to rebuilt machines with the same host names and IP addresses Manually copy your existing certificates to the restored system.
Restoring to a new system with different host names or IP addresses, and using custom certificates or storing your certificates in a non-default location. Create new certificates on the restored system before you restore Splunk UBA. By default, Splunk UBA looks for certificates in /var/vcap/caspida/certs. See Request and add a new certificate to Splunk UBA to access the Splunk UBA web interface in Install and Upgrade Splunk User Behavior Analytics.
Restoring to a new system with different host names or IP address, and using the default self-signed certificates or storing your certificates in the default location. Splunk UBA will create the proper certificate configuration for you so you don't need to create any new certificates.
Last modified on 15 March, 2021
Perform a full backup before upgrading or migrating Splunk UBA   Back up Splunk UBA using the backup script

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.4, 5.0.4.1, 5.0.5, 5.0.5.1, 5.1.0, 5.1.0.1, 5.2.0, 5.2.1, 5.3.0, 5.4.0, 5.4.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters