Installing the UEBA Content App for On-premises

For prerequisites, see UEBA Content App for On-premises.

To install the UEBA Content App for On-premises deployments (DA-ESS-UEBAContent), follow these steps:

  1. Go to Splunkbase and log in with your Splunk.com ID. You must be a licensed user to download the product.
  2. Download the UEBA Content App for On-premises (DA-ESS-UEBAContent) from Splunkbase.
  3. Choose Download, and save the app file to your desktop.
  4. Log in to the search head as an administrator.
    Note: Install the UEBA Content App for On-premises on the same search head as Splunk Enterprise Security.
  5. On the Splunk Enterprise search page, select Apps > Manage Apps and select Install App from File.
  6. Select Choose File and go to the UEBA product file.
  7. Select Upload to install.

For instructions on installing the UEBA Content App for On-premises in a search head cluster environment and for configuring the ueba_summaries index in an index cluster, see Install Splunk Enterprise Security in a search head cluster environment and Configure and deploy indexes for Splunk Enterprise Security.