Splunk® User Behavior Analytics

Install and Upgrade Splunk User Behavior Analytics

This documentation does not apply to the most recent version of Splunk® User Behavior Analytics. For documentation on the most recent version, go to the latest release.

How to install or upgrade to this release of Splunk UBA

Splunk UBA 5.4.1.1 is a patch release. Upgrading to Splunk UBA 5.4.1.1 requires Splunk UBA 5.4.1.

Use the following links for additional information:

Installing Splunk UBA on hardened operating systems is not supported.

This patch is only for 5.4.1 customers who connect their on-premises UBA with SplunkCloud, and who encountered an ES OutputConnector connectivity issue.

The fixed issue in this patch release is not included in UBA version 5.4.2, but will be available in UBA version 5.4.3. UBA version 5.4.3 is scheduled for release in late June 2025.

Users who require the fix included with the version 5.4.1.1 patch should not upgrade to version 5.4.2, but wait to upgrade to version 5.4.3.

Install or upgrade to this release of Splunk UBA

See the following table for information on how to install or upgrade to this release of Splunk UBA.

Your current deployment Your operating system How to get Splunk UBA 5.4.1.1
You are running Splunk UBA 5.4.1 Any Upgrade to Splunk UBA version 5.4.1.1
You are running Splunk UBA 5.4.0 Any Upgrade to Splunk UBA version 5.4.1.
You are running Splunk UBA 5.3.0 Any Upgrade to Splunk UBA version 5.4.0.
You are running Splunk UBA 5.2.0 or 5.2.1 Any Upgrade to Splunk UBA version 5.4.0.
You are running Splunk UBA 5.1.0 or 5.1.0.1. Any Upgrade to Splunk UBA version 5.2.0 or 5.3.0 and then upgrade to version 5.4.0.
You are running Splunk UBA 5.0.5 or 5.0.5.1 Any Upgrade to Splunk UBA version 5.1.0 and then upgrade to version 5.2.0 or 5.3.0, and then upgrade to version 5.4.0.
You are running a Splunk UBA release lower than 5.0.5 RHEL
OEL
  1. Upgrade to Splunk UBA 5.0.5.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.0.5 documentation for instructions.
  2. Upgrade to Splunk UBA 5.1.0.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.1.0 documentation for instructions.
  3. Upgrade to Splunk UBA 5.2.0 or 5.3.0. See Upgrade Splunk UBA prerequisites in Splunk UBA 5.2.0 documentation or Upgrade Splunk UBA prerequisites in Splunk UBA 5.3.0 documentation for instructions.
  4. Upgrade to Splunk UBA 5.4.0.
AMI or OVA
  1. Upgrade to Splunk UBA 5.0.5.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.0.5 documentation for instructions.
  2. Upgrade to Splunk UBA 5.1.0.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.1.0 documentation for instructions.
  3. Upgrade to Splunk UBA 5.2.0 or 5.3.0. See Upgrade Splunk UBA prerequisites in Splunk UBA 5.2.0 documentation or Upgrade Splunk UBA prerequisites in Splunk UBA 5.3.0 documentation for instructions.
  4. Upgrade to Splunk UBA 5.4.0.
You are deploying Splunk UBA for the first time RHEL
OEL
  1. Review the instructions in the Splunk UBA installation checklist.
  2. Select your deployment type and follow the instructions to Install Splunk User Behavior Analytics.
AMI

The AMI 5.4.0 install options become available 30 days after the general release of version 5.4.0.

  1. Review the instructions in the Splunk UBA installation checklist.
  2. Select your deployment type and follow the instructions to Install Splunk User Behavior Analytics.

If you are running a Splunk UBA version lower than 5.0.0, you must first upgrade to version 5.0.0, then upgrade to version 5.0.5, then upgrade to version 5.1.0, then to version 5.2.0 or 5.3.0, and then upgrade to version 5.4.0.

Last modified on 01 May, 2025
About Splunk User Behavior Analytics and release types   Splunk UBA installation checklist

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.4.1.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters