How to install or upgrade to this release of Splunk UBA

UBA 5.4.1.1

Splunk UBA 5.4.1.1 is a patch release. Upgrading to Splunk UBA 5.4.1.1 requires Splunk UBA 5.4.1.

This patch is only for 5.4.1 customers who connect their on-premises UBA with SplunkCloud, and who encountered an ES OutputConnector connectivity issue.

The fixed issue in this patch release is not included in UBA version 5.4.2, but will be available in UBA version 5.4.3. UBA version 5.4.3 is scheduled for release in late June 2025.

CAUTION: Users who require the fix included with the version 5.4.1.1 patch should not upgrade to version 5.4.2, but wait to upgrade to version 5.4.3.

UBA 5.4.1

Splunk UBA 5.4.1 is a maintenance and patch release. Use the following links for additional information:

  • See Welcome to Splunk UBA 5.4.1 in the Splunk User Behavior Analytics Release Notes manual for a summary of any new features or enhancements.
  • See Fixed Issues in Splunk UBA in the Splunk User Behavior Analytics Release Notes manual for a summary of any issues fixed in this release.

CAUTION: Installing Splunk UBA on hardened operating systems is not supported.

Install or upgrade to this release of Splunk UBA

See the following table for information on how to install or upgrade to this release of Splunk UBA.

Your current deployment Your operating system How to get Splunk UBA 5.4.1
You are running Splunk UBA 5.4.1 Any Upgrade to Splunk UBA version 5.4.1.1.
You are running Splunk UBA 5.4.0AnyUpgrade to Splunk UBA version 5.4.1.
You are running Splunk UBA 5.3.0 Any Upgrade to Splunk UBA version 5.4.0.
You are running Splunk UBA 5.2.0 or 5.2.1 Any Upgrade to Splunk UBA version 5.4.0.
You are running Splunk UBA 5.1.0 or 5.1.0.1. Any Upgrade to Splunk UBA version 5.2.0 or 5.3.0 and then upgrade to version 5.4.0.
You are running Splunk UBA 5.0.5 or 5.0.5.1 Any Upgrade to Splunk UBA version 5.1.0 and then upgrade to version 5.2.0 or 5.3.0, and then upgrade to version 5.4.0.
You are running a Splunk UBA release lower than 5.0.5 RHEL
OEL
  1. Upgrade to Splunk UBA 5.0.5.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.0.5 documentation for instructions.
  2. Upgrade to Splunk UBA 5.1.0.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.1.0 documentation for instructions.
  3. Upgrade to Splunk UBA 5.2.0 or 5.3.0. See Upgrade Splunk UBA prerequisites in Splunk UBA 5.2.0 documentation or Upgrade Splunk UBA prerequisites in Splunk UBA 5.3.0 documentation for instructions.
  4. Upgrade to Splunk UBA 5.4.0.
AMI or OVA
  1. Upgrade to Splunk UBA 5.0.5.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.0.5 documentation for instructions.
  2. Upgrade to Splunk UBA 5.1.0.
    See Upgrade Splunk UBA prerequisites in the Splunk UBA 5.1.0 documentation for instructions.
  3. Upgrade to Splunk UBA 5.2.0 or 5.3.0. See Upgrade Splunk UBA prerequisites in Splunk UBA 5.2.0 documentation or Upgrade Splunk UBA prerequisites in Splunk UBA 5.3.0 documentation for instructions.
  4. Upgrade to Splunk UBA 5.4.0.
You are deploying Splunk UBA for the first time RHEL
OEL
  1. Review the instructions in the Splunk UBA installation checklist.
  2. Select your deployment type and follow the instructions to Install Splunk User Behavior Analytics.
AMI

Note: The AMI 5.4.0 install options become available 30 days after the general release of version 5.4.0.
  1. Review the instructions in the Splunk UBA installation checklist.
  2. Select your deployment type and follow the instructions to Install Splunk User Behavior Analytics.

Note: If you are running a Splunk UBA version lower than 5.0.0, you must first upgrade to version 5.0.0, then upgrade to version 5.0.5, then upgrade to version 5.1.0, then to version 5.2.0 or 5.3.0, and then upgrade to version 5.4.0.