All Apps and Add-ons

Deploy Splunk UBA in Mixed Server OS env?

bkwoka
Explorer

My current environment is 2 splunk servers. One acting as a search head / indexer and one acting as a heavy forwarder. I have multiple UF clients pointing to the HF which filters and forwards to the indexer. Both of the servers are Windows Server 2016. I am looking into what would be needed to start using UBA. I see that it requires a *nix server. Could I deploy a second indexer on a *nix server and use that for UBA and continue to use the Windows search head?

0 Karma

cmeisch
Path Finder

This question is old but never answered:
Short answer... NO in most cases. UBA is a separate platform from SPLUNK core (UBA runs on top of Hadoop if you will). After going through the setup of UBA, etc I can tell you that you will want the system(s) running UBA to be its own separate instance. See the sizing guide: Install guide

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...