All Apps and Add-ons

What are the system requirements for Splunk User Behavior Analytics (Splunk UBA)?

KISHORE_LK
Explorer

What are the system requirements for the Splunk UBA product? Is this an app thats installed on top of Splunk Enterprise or is this a standalone product/device that works with Splunk.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

ncaster
New Member

Does these HW requirements apply to a 3 server deployment ?
Do I need 3x64GB RAM?

0 Karma

David
Splunk Employee
Splunk Employee

@ncaster Yes, each server in the deployment needs to match the required hardware config.

0 Karma

David
Splunk Employee
Splunk Employee

For anyone else who comes across this, keep in mind that the OS Versions will change over time. At present (May 2016), we support CentOS / RHEL 6.7 and 7.2. Check the latest version of the UBA installation docs, as noted above.

0 Karma

KISHORE_LK
Explorer

Is the licensing of this product based on data volume, similar to Splunk Enterprise?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Licensing is based on each account within your environment. Think of your AD accounts such as user accounts, service accounts etc...any that are authenticating in your environment.

0 Karma

KISHORE_LK
Explorer

Thanks Daniels

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...