Splunk® User Behavior Analytics

Install and Upgrade Splunk User Behavior Analytics

Acrobat logo Download manual as PDF

This documentation does not apply to the most recent version of Splunk® User Behavior Analytics. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Verify a successful upgrade of Splunk UBA

After upgrading Splunk UBA, verify a successful upgrade.

Data sources

Verify all the data sources that were processing before the upgrade are running and processing data.

  1. Log in to Splunk UBA in a web browser.
  2. From the Splunk UBA toolbar, select Manage > Data Sources.
  3. Verify that data sources are processing data and EPS is not zero.

Review the upgrade script output

If the upgrade failed, review the output from the upgrade script. Splunk UBA Web does not load if the upgrade is unsuccessful.

  1. Review the output from the upgrade script in /var/log/caspida/upgrade.out.
  2. If needed, work with Splunk Support to resolve upgrade errors.

After resolving errors with the upgrade, run the upgrade script again. The upgrade script skips successful steps and only runs failed steps again.

Review the Health Monitor dashboard

Verify that all Splunk UBA services are running on the Health Monitor dashboard to confirm a successful upgrade.

  1. Select System > Health Monitor to review the Health Monitor dashboard.

See Monitor the health of your Splunk UBA deployment in the Administer Splunk User Behavior Analytics manual.

Last modified on 08 August, 2023
Upgrade a Splunk UBA deployment that is using warm standby
Configure Splunk UBA

This documentation applies to the following versions of Splunk® User Behavior Analytics:, 5.1.0,, 5.2.0, 5.2.1

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters