My current environment is 2 splunk servers. One acting as a search head / indexer and one acting as a heavy forwarder. I have multiple UF clients pointing to the HF which filters and forwards to the indexer. Both of the servers are Windows Server 2016. I am looking into what would be needed to start using UBA. I see that it requires a *nix server. Could I deploy a second indexer on a *nix server and use that for UBA and continue to use the Windows search head?
This question is old but never answered:
Short answer... NO in most cases. UBA is a separate platform from SPLUNK core (UBA runs on top of Hadoop if you will). After going through the setup of UBA, etc I can tell you that you will want the system(s) running UBA to be its own separate instance. See the sizing guide: Install guide