Splunk® User Behavior Analytics

Install and Upgrade Splunk User Behavior Analytics

About Splunk User Behavior Analytics and release types

The following types of Splunk UBA releases are available:

  • Platform releases
  • Maintenance and patch releases

Platform releases

Platform releases contain significant new features and enhancements such as new or enhanced rules, threats, or product functionality. Platform releases are identified with a zero at the end of the three-digit release number, such as 5.2.0, 5.3.0, or 5.4.0.

Platform releases are installed by performing the following tasks:

  1. Downloading the software from the Splunk UBA Software Update page on Splunkbase.
  2. Deploy the software into a new environment, or upgrade existing software by following the upgrade instructions.

You can also obtain the platform release software for RHEL and other environments from the Splunk UBA Software Installation Package page on Splunkbase.

Maintenance and patch releases

Maintenance releases contain a longer list of known issues, bug fixes, and minor feature additions or enhancements. Maintenance releases are identified by a three-digit release number that does not end in a zero such as 5.4.1, which is a maintenance release for the platform release 5.4.0.

A patch release consists of up to five critical or highly urgent issues that must be addressed in a short window of time. Patch releases are identified by a four-digit release number such as, which is a patch release for Splunk UBA release 5.1.0.

Maintenance and patch releases are installed by performing the following tasks:

  1. Download the software from the Splunk UBA Software Update page on Splunkbase.
  2. Install the software using the CLI to execute a script.
Last modified on 30 August, 2024
  How to install or upgrade to this release of Splunk UBA

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.4.0, 5.4.1

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters