Splunk Enterprise

Cluster master environment

Patrycja_K_
Engager

I would like to ask about the server.conf and web.conf configuration files.
how to place them in a clustered environment where there are 3 indexers and the cluster master stands alone? thanks for the answers.

Labels (2)
Tags (1)
0 Karma

meetmshah
SplunkTrust
SplunkTrust

Ideally it should be managed locally in system/local - however, have you tried managing it through peer-apps? As peer-apps' Precedence will be as follow - 

1. Peer-app local directories -- highest priority
2. System local directory
3. App local directories
4. Peer-app default directories
5. App default directories
6. System default directory -- lowest priority

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles#Precedenc...

Please accept the solution and hit Karma, if this helps!

meetmshah
SplunkTrust
SplunkTrust

Hello @Patrycja_K_ typically, server.conf and web.conf file is for below - 

  1. server.conf:

    • This file contains configurations related to the Splunk server, such as network settings, authentication settings etc.
    • You typically only need to manage this file on the cluster master.
  2. web.conf:

    • This file contains configurations for the Splunk Web interface, such as UI settings, SSL settings, and HTTP server settings.
    • Similarly, you typically manage this file on the cluster master.

Can you please share if you have any specific question about server.conf and web.conf files?

Patrycja_K_
Engager

let's say that I have clustered for my indexers and now I want to change the configuration for peers regarding web.conf from the master node level (disable the indexers gui because there is now a cluster master manages them) and add config to server.conf from the cluster master level for the entire cluster. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...