<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Heavy on forwarder license in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705186#M20923</link>
    <description>&lt;P&gt;L.s.,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At our company we have multiple heavy forwarders. Normaly they talk to the central license manager, but for migrtation reason whe have to get them talking to themself. So a forwarder license is in order i think.&lt;/P&gt;
&lt;P&gt;looks like an easy process. I did below&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;./splunk edit licenser-groups Forwarder -is_active 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;this will set in /opt/splunk/etc/system/local/server.conf&amp;nbsp; the settings below:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[license]

active_group = Forwarder&lt;/LI-CODE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder&lt;/LI-CODE&gt;
&lt;P&gt;Have to set by myself &lt;EM&gt;master_uri = self&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;restart the server and it looks like a go.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;When i do this on every heavy it will give the error in _internal&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Duplicate&lt;/SPAN&gt; &lt;SPAN class=""&gt;license&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;hash:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD&lt;/SPAN&gt;], &lt;SPAN class=""&gt;also&lt;/SPAN&gt; &lt;SPAN class=""&gt;present&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;peer .&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;And&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Duplicated license situation not fixed in time (72-hour grace period). Disabling peer..&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Why?? Is it realy going to disable the forwarders when it uses the forwarder.license? What to do about it, where did i go wrong?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;greetz&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Jari&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 15:13:55 GMT</pubDate>
    <dc:creator>jariw</dc:creator>
    <dc:date>2024-11-25T15:13:55Z</dc:date>
    <item>
      <title>Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705186#M20923</link>
      <description>&lt;P&gt;L.s.,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At our company we have multiple heavy forwarders. Normaly they talk to the central license manager, but for migrtation reason whe have to get them talking to themself. So a forwarder license is in order i think.&lt;/P&gt;
&lt;P&gt;looks like an easy process. I did below&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;./splunk edit licenser-groups Forwarder -is_active 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;this will set in /opt/splunk/etc/system/local/server.conf&amp;nbsp; the settings below:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[license]

active_group = Forwarder&lt;/LI-CODE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder&lt;/LI-CODE&gt;
&lt;P&gt;Have to set by myself &lt;EM&gt;master_uri = self&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;restart the server and it looks like a go.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;When i do this on every heavy it will give the error in _internal&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Duplicate&lt;/SPAN&gt; &lt;SPAN class=""&gt;license&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;hash:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD&lt;/SPAN&gt;], &lt;SPAN class=""&gt;also&lt;/SPAN&gt; &lt;SPAN class=""&gt;present&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;peer .&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;And&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Duplicated license situation not fixed in time (72-hour grace period). Disabling peer..&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Why?? Is it realy going to disable the forwarders when it uses the forwarder.license? What to do about it, where did i go wrong?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;greetz&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Jari&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 15:13:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705186#M20923</guid>
      <dc:creator>jariw</dc:creator>
      <dc:date>2024-11-25T15:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705195#M20924</link>
      <description>&lt;P class="lia-align-left"&gt;Please remove parameter&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;master_uri = self&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;and try it again. If you get the same error please execute&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;splunk btool server list license --debug&lt;/PRE&gt;&lt;P&gt;and share the output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 14:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705195#M20924</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-11-25T14:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705271#M20932</link>
      <description>&lt;P&gt;Thanks for the response Paul..&lt;/P&gt;&lt;P&gt;I removed the master_uri. I can understand why, it is now manager_uri see below:&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/local/server.conf [license]&lt;BR /&gt;/opt/splunk/etc/system/local/server.conf active_group = Forwarder&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf connection_timeout = 30&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf manager_uri = self&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf receive_timeout = 30&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf report_interval = 1m&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf send_timeout = 30&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf squash_threshold = 2000&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf strict_pool_quota = true&lt;/P&gt;&lt;P&gt;I did something else, and that is remove the heavy's from the distributed search peers. Why they where there i don't know. It resolved one thing, the warning about disabling the peer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing remaining is the duplicate license hash (ffffff...) in the _internal index. I can understand the hash itself. Every forwaredr with this license has this hash. What i don't understand is why this warnimng. And it is only the warning for the heavy's&amp;nbsp; which were in the distributed serach peers. Not the one's which were not in that list. It seems something remained&amp;nbsp; someweher and keeps looking to the license on these heavy's and keeps reporting it is the same license...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 09:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705271#M20932</guid>
      <dc:creator>jariw</dc:creator>
      <dc:date>2024-11-26T09:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705275#M20933</link>
      <description>&lt;P&gt;Okay, just to confirm master_uri and manager_uri is not set on the HF, right?&lt;/P&gt;&lt;P&gt;Could you check what files are located under etc/licenses?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 09:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705275#M20933</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-11-26T09:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705278#M20934</link>
      <description>&lt;P&gt;I have a heavy's without master_uri and Manager_uri. They are luckely working okay besides the error.&lt;/P&gt;&lt;P&gt;In etc/licenses is only&amp;nbsp;download-trial folder. No forwarder.license&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 10:45:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705278#M20934</guid>
      <dc:creator>jariw</dc:creator>
      <dc:date>2024-11-26T10:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705280#M20935</link>
      <description>&lt;P&gt;Okay. Could you check/verify if you use the Distributed Monitoring Console and if the affected HFs are configured as Indexer under Settings --&amp;gt; Monitoring Console --&amp;gt; Settings --&amp;gt; General Setup?&amp;nbsp;&lt;/P&gt;&lt;P&gt;That could be the reason why the HeavyForwarder are configured as distributed search peers to monitor them in the DMC.&lt;/P&gt;&lt;P&gt;So if the license manager on the same instance as the DMC is check the config files for the affected HFs and may remove them.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 10:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705280#M20935</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-11-26T10:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy on forwarder license</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705469#M20940</link>
      <description>&lt;P&gt;I just found it in a few files inside the&amp;nbsp;:&lt;/P&gt;&lt;P&gt;./apps/splunk_monitoring_console/lookups/hwf-list.csv&lt;/P&gt;&lt;P&gt;./apps/splunk_monitoring_console/lookups/dmc_forwarder_assets.csv&lt;/P&gt;&lt;P&gt;./apps/splunk_monitoring_console/lookups/dmc_forwarder_assets.csv.c&lt;/P&gt;&lt;P&gt;didn't removed them yet. The fact is we are going to rebuild the dmc/lm in a matter of weeks and wil see if these errors wil appear again. But i think they won't appear again. Until now it doesn't seem to matter, it all works great.&lt;/P&gt;&lt;P&gt;grts&lt;/P&gt;&lt;P&gt;jari&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 07:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Heavy-on-forwarder-license/m-p/705469#M20940</guid>
      <dc:creator>jariw</dc:creator>
      <dc:date>2024-11-28T07:56:39Z</dc:date>
    </item>
  </channel>
</rss>

