Splunk UBA 备份很重要,里面有系统的配置,还有license 配置,还有sso 等,还是很重要的,否则重新来过,耗时又费力,下面先讲怎么备份:
1: 单机备份的话,很简单:
Back up Splunk UBA using the backup script - Splunk Documentation
Below is an example backup.
-
Log in to the management node of your Splunk UBA deployment as caspida using SSH.
- Navigate to the
/opt/caspida/bin/utils
folder:cd /opt/caspida/bin/utils
- Run the backup script. Below is the command and its output:
[caspida@uba bin]$ ./uba-backup.sh --no-prestart --archive --archive-type tgz UBA Backup Script - Version 2.1.5 Backup started at: Thu Oct 8 07:44:59 UTC 2020 Backup running on: uba-backup.splunk.com Logfile: