Splunk User Behavior Analytics

How to identify Management Node (or) Master node in a existing distributed UBA Deployment of 10 nodes

VasukiPramod
Explorer

Hi Team,

How do I identify the management node or master node in an existing distributed UBA Deployment (7 node or 10 node or 20 node)

https://docs.splunk.com/Documentation/UBA/5.0.3/Install/TSUBAServicesNodes doesn't have details about the same.

0 Karma

lakshman239
Influencer

In a distributed setup, generally node 1 / ubanode1 is the master node.  ( You can also see them in /etc/hosts file).  

In the caspida-deployment.conf file referred in the above link, look for 'container.master.host' and that should indicate your master node and match with node1 in /etc/hosts. Additionally, if you go to UI, System->Cluster->Cluster services, search for UI and that will give the node as well [ assuming UI is setup on master, which is normally the case]

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...