All Apps and Add-ons

What are the system requirements for Splunk User Behavior Analytics (Splunk UBA)?

KISHORE_LK
Explorer

What are the system requirements for the Splunk UBA product? Is this an app thats installed on top of Splunk Enterprise or is this a standalone product/device that works with Splunk.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

Please take a look at our online documentation for system requirements - http://docs.splunk.com/Documentation/UBA/2.1.0/Install/Requirements . There is a Splunk UBA app that is installed on the Splunk Platform, however it does add its own server or servers to the overall Splunk architecture depending on the deployment size.

Hardware requirements

You can install Splunk UBA on a physical server, a virtual machine, or in the cloud. You must have sudo access to the server. Wherever you install Splunk UBA, the machine must meet the following requirements.

50 GB disk space for the Splunk UBA installation.
500 GB partition or additional disk space for metadata storage.
16 CPU cores.
64 GB RAM.

Operating system requirements

Splunk UBA can only be installed on a server that uses one of the following 64-bit Linux distributions:

Ubuntu 14.04.3 LTS
RedHat Server 6.6
CentOS Server 6.6

The Open Virtual Appliance (OVA) format provided for virtual installations includes 64-bit Ubuntu 14.04.3 LTS.

View solution in original post

ncaster
New Member

Does these HW requirements apply to a 3 server deployment ?
Do I need 3x64GB RAM?

0 Karma

David
Splunk Employee
Splunk Employee

@ncaster Yes, each server in the deployment needs to match the required hardware config.

0 Karma

David
Splunk Employee
Splunk Employee

For anyone else who comes across this, keep in mind that the OS Versions will change over time. At present (May 2016), we support CentOS / RHEL 6.7 and 7.2. Check the latest version of the UBA installation docs, as noted above.

0 Karma

KISHORE_LK
Explorer

Is the licensing of this product based on data volume, similar to Splunk Enterprise?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Licensing is based on each account within your environment. Think of your AD accounts such as user accounts, service accounts etc...any that are authenticating in your environment.

0 Karma

KISHORE_LK
Explorer

Thanks Daniels

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!