Installation

Splunk UBA deployment Requirement

AtherAD
Engager

Hi Team,

I am trying to deploy the Splunk UBA node, but I get a bit confused because, in the Splunk UBA operating system requirements, I didn't find whether Red Hat 8.10 or 9.2 was supported or not.  I only found the below information. How can I determine if Red Hat 8.10 or 9.2 are supported or not?

Operating System: Red Hat Enterprise Linux (RHEL) 8.8
Kernel-Version Tested: 4.18.0-477.10.1.el8_8.x86_64,
4.18.0-372.9.1.el8.x86_64

Labels (1)
0 Karma

YoungN
Splunk Employee
Splunk Employee

Red Hat 8.10 or 9.2 are not support as of yet, however you can try an install based on the older kernel version "4.18.0-477.27.1.el8_8.x86_64" that is supported. I have had some luck before by using the older kernel with an updated system but know that its not supported. 

**There may be some bugs that haven't been tested yet by doing this but it will allow you to install.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AtherAD ,

We're deploying UBA and we had an instalation with Red Hat 8.8, with some packets in 8.9 and doesn't run!

Splunk Support confirmed that you must ne use that (with the present UBA release) all the packets will be the ones in the certified release, e.g. RedHat 8.8 without any update to greater releases.

And you must block all the updates, otherwise the installation will stop to run.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...