All Apps and Add-ons

Deploy Splunk UBA in Mixed Server OS env?

bkwoka
Explorer

My current environment is 2 splunk servers. One acting as a search head / indexer and one acting as a heavy forwarder. I have multiple UF clients pointing to the HF which filters and forwards to the indexer. Both of the servers are Windows Server 2016. I am looking into what would be needed to start using UBA. I see that it requires a *nix server. Could I deploy a second indexer on a *nix server and use that for UBA and continue to use the Windows search head?

0 Karma

cmeisch
Path Finder

This question is old but never answered:
Short answer... NO in most cases. UBA is a separate platform from SPLUNK core (UBA runs on top of Hadoop if you will). After going through the setup of UBA, etc I can tell you that you will want the system(s) running UBA to be its own separate instance. See the sizing guide: Install guide

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...