All Apps and Add-ons

What are the system requirements for Splunk User Behavior Analytics (Splunk UBA)?

KISHORE_LK
Explorer

What are the system requirements for the Splunk UBA product? Is this an app thats installed on top of Splunk Enterprise or is this a standalone product/device that works with Splunk.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

ncaster
New Member

Does these HW requirements apply to a 3 server deployment ?
Do I need 3x64GB RAM?

0 Karma

David
Splunk Employee
Splunk Employee

@ncaster Yes, each server in the deployment needs to match the required hardware config.

0 Karma

David
Splunk Employee
Splunk Employee

For anyone else who comes across this, keep in mind that the OS Versions will change over time. At present (May 2016), we support CentOS / RHEL 6.7 and 7.2. Check the latest version of the UBA installation docs, as noted above.

0 Karma

KISHORE_LK
Explorer

Is the licensing of this product based on data volume, similar to Splunk Enterprise?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Licensing is based on each account within your environment. Think of your AD accounts such as user accounts, service accounts etc...any that are authenticating in your environment.

0 Karma

KISHORE_LK
Explorer

Thanks Daniels

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...