Manager node configuration overview
You initially configure the manager node when you enable it, as described in "Enable the managernode". This is usually all the configuration the manager node needs.
Change the configuration
If you need to edit the configuration, you have these choices:
- You can edit the configuration from the manager node dashboard in Splunk Web. See "Configure the manager node with the dashboard".
- You can directly edit the
[clustering]stanza in the manager's
server.conffile. To configure some advanced settings, you must edit this file. See "Configure the manager node with server.conf".
- You can use the CLI. See "Configure the manager node with the CLI".
After you change the manager node configuration, you must restart the manager for the changes to take effect.
Important: The manager node has the sole function of managing the other cluster nodes. Do not use it to index external data or to search the cluster.
Changes that require caution
Be careful when making changes to these settings:
- Replication factor and search factor. It is inadvisable to increase either of these settings after your indexer cluster contains significant amounts of data. This will kick off a great deal of bucket activity, affecting the cluster's performance adversely while bucket copies are being created or made searchable.
- Heartbeat timeout. Do not change the
heartbeat_timeoutattribute from its default value of 60 (seconds) unless instructed to do so by Splunk Support. In particular, do not decrease it. This can overload the peers.
Configure a stand-by manager node
To prepare for manager node failure, configure a stand-by manager node that can take over if the current manager goes down. See "Replace the manager node on the indexer cluster".
Configure a multisite manager node
A multisite manager node has a number of configuration differences and additions, compared to a basic, single-site cluster. See "Configure multisite indexer clusters with server.conf".
Configure and manage the indexer cluster with the CLI
Configure the manager node with the dashboard
This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 9.0.0, 9.0.1