Security

Find out the role of a Splunk server

New Member

Hello,

I have 2 servers on which Splunk is installed. I am able to access the Splunk console using splunk2 server.

In the DMC, only splunk2 shows up in the standalone mode with the following server roles:
Indexer
License Master
Deployment Server
Search Head

I cannot access the Splunk console using splunk1 server and I am assuming that is because Splunk web is disabled for this server.

The setup was done earlier and I am now trying to upgrade the instance to the latest version. Before planning the upgrade, I would like to understand what role does splunk1 play in the setup.

Is there a way to find out this information?

Thanks

Tags (2)
0 Karma

Champion

Hi

Here https://docs.splunk.com/Documentation/Splunk/8.0.1/InheritedDeployment/Introduction is an instruction how to spelunking what you have on your hands.

R. Ismo

0 Karma

Path Finder

Or if you don't care to see all of those fields:
| rest splunkserver=local /services/search/distributed/peers/
|table splunk
server server_roles version

However this query may not list roles for any of:
cluster master
license server
deployment server
monitoring console

0 Karma

Splunk Employee
Splunk Employee

The only thing missing from splunk2 is indexer. I believe that this search will list your search peers (indexers), I do not have a distributed env to test on, but it is from the DMC App saved searches:

| rest splunk_server=local /services/search/distributed/peers/

Alternatively, just run any search and look at the splunk_server field, which identifies the server where the data lives.

0 Karma