- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Deploy Splunk UBA in Mixed Server OS env?
My current environment is 2 splunk servers. One acting as a search head / indexer and one acting as a heavy forwarder. I have multiple UF clients pointing to the HF which filters and forwards to the indexer. Both of the servers are Windows Server 2016. I am looking into what would be needed to start using UBA. I see that it requires a *nix server. Could I deploy a second indexer on a *nix server and use that for UBA and continue to use the Windows search head?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

This question is old but never answered:
Short answer... NO in most cases. UBA is a separate platform from SPLUNK core (UBA runs on top of Hadoop if you will). After going through the setup of UBA, etc I can tell you that you will want the system(s) running UBA to be its own separate instance. See the sizing guide: Install guide
