Welcome to Splunk UBA 5.3.0
Splunk UBA 5.3.0 is a major release. See About Splunk User Behavior Analytics and release types for more information about the different types of Splunk UBA releases.
If you are new to Splunk UBA, review all the steps in the Splunk UBA installation checklist before installing Splunk UBA.
The introduction of UBA 5.3.0 means the End of Support for UBA 5.0.x versions. For more information, see the Splunk Software Support Policy
Planning to upgrade from an earlier version?
If you plan to upgrade to this version from an earlier version of Splunk UBA, read the following documents before you get started:
- See Upgrade Splunk UBA prerequisites and overview in the Install and Upgrade Splunk user Behavior Analytics manual for information you need to know before you upgrade.
- Splunk UBA requires incremental upgrades from earlier versions. See How to install or upgrade to this release of Splunk UBA in the Install and Upgrade Splunk User Behavior Analytics manual for upgrade path information.
What's new in 5.3.0
Splunk UBA version 5.3.0 includes the following features and changes:
Feature, enhancement, or change | Description |
---|---|
Operating System updates: | The 5.3.0 release provides the following operating system updates:
The 5.3.0 AMI install package is available shortly after GA for AWS environments. For more information, see Operating system requirements in the Install and Upgrade Splunk User Behavior Analytics manual. |
20 Node XL cluster | A new 20 node cluster option is now available. This 20 Node XL cluster is a vertically scaled-up version of the current 20 node "Classic" option. The XL option offers increased events-per-second (EPS) support up to 160K, supports up to 750K accounts, and up to 1M devices.
To learn more, see About the 20 Node XL option in the Plan and Scale your Splunk UBA Deployment manual. |
New and enhanced UBA models | |
Health Monitor new indicator | New indicator for backup disk utilization in the Health Monitor user interface. |
Security enhancements |
|
MaxMind database refresh | The Maxmind GeoLite2-City DB GeoLite2-City_20230718 (07/18/2023) is bundled with UBA 5.3.0.
User can keep the Maxmind DB up to date by following these instructions: https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591635 |
Splunk UBA external dependencies
You can download a PDF file listing the external dependencies required to install Splunk UBA:
Do not independently upgrade the following UBA-dependent components to avoid impacting UBA operations:
docker
hadoop
hive
impala
influxdb
kafka
kubernetes
nodejs
openjdk
postgresql
protobuf
redis
spark
zookeeper
Known issues in Splunk UBA |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.3.0
Feedback submitted, thanks!