Splunk® User Behavior Analytics Kafka Ingestion App

Splunk UBA Kafka Ingestion App

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Install the Splunk UBA Kafka Ingestion App

The Splunk UBA Kafka Ingestion App must be installed on the Splunk search head. Obtain the app from Splunkbase. You can search to see if this app is already installed from the Splunk Enterprise home page. See Where to get more apps and add-ons in the Splunk Enterprise Admin Manual.

If your environment includes multiple search heads, install the Splunk UBA Kafka Ingestion App on each search head. If you have a clustered Splunk environment, you can install this app on the search head cluster. See Use the deployer to distribute apps and configuration updates in the Splunk Enterprise Distributed Search manual.

After downloading the Splunk UBA Kafka Ingestion App and verifying the prerequisites, install the app using either Splunk Web or directly from the downloaded file.

Install the app on Splunk Enterprise using Splunk Web

Perform the following steps to install the Splunk UBA Kafka Ingestion App on Splunk Enterprise using Splunk Web:

  1. Log in to the Splunk Enterprise search head.
  2. On the Applications menu, scroll to the bottom and select Find More Apps.
  3. On the Browse more apps page, locate the app in the list, or type the name in the search box.
  4. Provide your splunk.com credentials.
  5. Accept the license terms.
  6. Click Login and Install.
  7. Click Done.
  8. Restart Splunk Enterprise to complete the installation.

Install the app on Splunk Enterprise from a downloaded file

Perform the following steps to install the Splunk UBA Kafka Ingestion App on Splunk Enterprise using a downloaded file:

  1. Log in to splunkbase.splunk.com.
  2. Download the Splunk UBA Kafka Ingestion App and save it to an accessible location.
  3. Log in to the Splunk Enterprise search head.
  4. On the Applications menu, select the Mange Apps (The manage apps icon) icon.
  5. On the Apps page, click Install app from file.
  6. On the Upload app page, click the Choose file button to locate the app.
  7. Click Upload.
  8. Click Done.
  9. Restart Splunk Enterprise to complete the installation.

Install the app on the Splunk Cloud Platform

The procedure for installing apps and add-ons for use with your Splunk Cloud Platform instance depends on the version of Splunk Cloud Platform that you are running. Access the version of this documentation that matches the version of your Splunk Cloud Platform deployment, then follow the directions. See Install apps on your Splunk Cloud Platform deployment in the Splunk Cloud Platform Admin Manual for the latest instructions.

Last modified on 25 January, 2022
PREVIOUS
Requirements for Kafka data ingestion
  NEXT
Enable Kafka data ingestion

This documentation applies to the following versions of Splunk® User Behavior Analytics Kafka Ingestion App: 1.4, 1.4.1, 1.4.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters