Splunk User Behavior Analytics

How to identify Management Node (or) Master node in a existing distributed UBA Deployment of 10 nodes

VasukiPramod
Explorer

Hi Team,

How do I identify the management node or master node in an existing distributed UBA Deployment (7 node or 10 node or 20 node)

https://docs.splunk.com/Documentation/UBA/5.0.3/Install/TSUBAServicesNodes doesn't have details about the same.

0 Karma

lakshman239
Influencer

In a distributed setup, generally node 1 / ubanode1 is the master node.  ( You can also see them in /etc/hosts file).  

In the caspida-deployment.conf file referred in the above link, look for 'container.master.host' and that should indicate your master node and match with node1 in /etc/hosts. Additionally, if you go to UI, System->Cluster->Cluster services, search for UI and that will give the node as well [ assuming UI is setup on master, which is normally the case]

Get Updates on the Splunk Community!

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...