Installing the UEBA Content App for On-premises
For prerequisites, see UEBA Content App for On-premises.
To install the UEBA Content App for On-premises deployments (DA-ESS-UEBAContent), follow these steps:
- Go to Splunkbase and log in with your Splunk.com ID. You must be a licensed user to download the product.
- Download the UEBA Content App for On-premises (DA-ESS-UEBAContent) from Splunkbase.
- Choose Download, and save the app file to your desktop.
- Log in to the search head as an administrator.
Note: Install the UEBA Content App for On-premises on the same search head as Splunk Enterprise Security.
- On the Splunk Enterprise search page, select Apps > Manage Apps and select Install App from File.
- Select Choose File and go to the UEBA product file.
- Select Upload to install.
For instructions on installing the UEBA Content App for On-premises in a search head cluster environment and for configuring the ueba_summaries index in an index cluster, see Install Splunk Enterprise Security in a search head cluster environment and Configure and deploy indexes for Splunk Enterprise Security.