Have you already completed the installation of UBA or are you simply running the pre-check script for the first time prior to installation? If prior to installation, some errors are expected. See the relevant docs here: https://docs.splunk.com/Documentation/UBA/5.0.4/Install/CheckSystemStatus You might see errors related to file-based configurations. Those configurations happen after setup, so you can ignore those errors when running the script before setting up Splunk UBA. I recently completed a UBA clustered setup on RHEL. I don't recall whether we saw the symlink or /var/log errors, but I do remember seeing the eth0 error. That eth0 message went away after installation. If you haven't installed yet, I think you are likely safe to proceed. Run the script again after installation to verify everything is set up correctly.
... View more