Splunk User Behavior Analytics

How to identify Management Node (or) Master node in a existing distributed UBA Deployment of 10 nodes

VasukiPramod
Explorer

Hi Team,

How do I identify the management node or master node in an existing distributed UBA Deployment (7 node or 10 node or 20 node)

https://docs.splunk.com/Documentation/UBA/5.0.3/Install/TSUBAServicesNodes doesn't have details about the same.

0 Karma

lakshman239
Influencer

In a distributed setup, generally node 1 / ubanode1 is the master node.  ( You can also see them in /etc/hosts file).  

In the caspida-deployment.conf file referred in the above link, look for 'container.master.host' and that should indicate your master node and match with node1 in /etc/hosts. Additionally, if you go to UI, System->Cluster->Cluster services, search for UI and that will give the node as well [ assuming UI is setup on master, which is normally the case]

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...