What are the system requirements for the Splunk UBA product? Is this an app thats installed on top of Splunk Enterprise or is this a standalone product/device that works with Splunk.
Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.
You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.
50 GB disk space for the Splunk UBA installation. 500 GB partition or additional disk space for metadata storage. 16 CPU cores. 64 GB RAM.
Operating system requirements
Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:
Ubuntu 14.04.3 LTS RedHat Server 6.6 CentOS Server 6.6
The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.
Is the licensing of this product based on data volume, similar to Splunk Enterprise?
Licensing is based on each account within your environment. Think of your AD accounts such as user accounts, service accounts etc...any that are authenticating in your environment.
For anyone else who comes across this, keep in mind that the OS Versions will change over time. At present (May 2016), we support CentOS / RHEL 6.7 and 7.2. Check the latest version of the UBA installation docs, as noted above.
Does these HW requirements apply to a 3 server deployment ?
Do I need 3x64GB RAM?
@ncaster Yes, each server in the deployment needs to match the required hardware config.