Splunk User Behavior Analytics

How to identify Management Node (or) Master node in a existing distributed UBA Deployment of 10 nodes


Hi Team,

How do I identify the management node or master node in an existing distributed UBA Deployment (7 node or 10 node or 20 node)

https://docs.splunk.com/Documentation/UBA/5.0.3/Install/TSUBAServicesNodes doesn't have details about the same.

0 Karma


In a distributed setup, generally node 1 / ubanode1 is the master node.  ( You can also see them in /etc/hosts file).  

In the caspida-deployment.conf file referred in the above link, look for 'container.master.host' and that should indicate your master node and match with node1 in /etc/hosts. Additionally, if you go to UI, System->Cluster->Cluster services, search for UI and that will give the node as well [ assuming UI is setup on master, which is normally the case]

Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...