splunk-uba-setup

Validates Splunk UBA/UEBA readiness and reports migration guidance to ES Premier.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-uba-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-uba-setup
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-uba-setup
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-uba-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires install_app.sh, credential_helpers.sh, and includes scripts (resource) components.

## What problem does it solve? Use when validating Splunk UBA / UEBA readiness, optional UBA Kafka ingestion app placement, and migration guidance to Splunk Enterprise Security Premier UEBA without installing standalone UBA servers.

## Core Features & Use Cases

  • Validate UBA/UEBA readiness and availability of ES Premier UEBA migration guidance.
  • Provide optional installation guidance for the Splunk UBA Kafka Ingestion App.
  • Report end-of-sale and end-of-support status; guide transition toward ES Premier UEBA.

### Quick Start Run a dry-run to validate readiness and, if needed, install the Kafka ingestion app using the setup script.

Frequently Asked Questions about splunk-uba-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate Splunk UBA readiness before starting a migration?

Validate Splunk UBA readiness by running a dry-run workflow that checks Splunk REST APIs for support apps and indexes, identifying migration gaps and handoff considerations for your environment.

Can I migrate to Splunk Enterprise Security Premier UEBA without installing standalone UBA servers?

Yes, you can assess ES Premier UEBA readiness without standalone UBA servers by generating migration guidance and reviewing end-of-sale and end-of-support status reporting for your Splunk environment.

Do I need the Splunk UBA Kafka Ingestion App to check UEBA readiness?

The Splunk UBA Kafka Ingestion App is optional for UEBA readiness checks, providing optional installation guidance and placement validation only when Kafka ingestion is explicitly requested.

What Splunk API access is required to check UEBA readiness gaps?

Checking UEBA readiness gaps requires access to Splunk REST APIs to execute the validation workflow, verify support apps and indexes, and generate accurate migration guidance.

What is the best way to plan a Splunk UBA to ES Premier UEBA migration?

The best way to plan a Splunk UBA to ES Premier UEBA migration is to validate readiness gaps first, determine optional Kafka app placement, and follow the generated end-of-sale reporting and migration guidance.