<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cloud Built-in License Alert broken in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355662#M21306</link>
    <description>&lt;P&gt;These alerts are now removed in version 7.0.1 which will be released in the future&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2017 18:50:14 GMT</pubDate>
    <dc:creator>ytenenbaum_splu</dc:creator>
    <dc:date>2017-11-09T18:50:14Z</dc:date>
    <item>
      <title>Splunk Cloud Built-in License Alert broken</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355659#M21303</link>
      <description>&lt;P&gt;I am working on a Splunk Cloud deployment and have attempted to enable the built-in (splunk_instance_monitoring) alerts for license violations.&lt;/P&gt;

&lt;P&gt;I have stripped away the bulk of the alert search to locate the broken component and it at the very front&lt;/P&gt;

&lt;P&gt;| rest splunk_server_group=sim_group_license_master /services/licenser/pools &lt;/P&gt;

&lt;P&gt;It appears that there is no such group as sim_group_license_master or at the least, it returns no data.&lt;/P&gt;

&lt;P&gt;I have also attempted the License Monitor app off splunkbase and this uses the same rest endpoint.&lt;/P&gt;

&lt;P&gt;How do I get this alert to work.&lt;BR /&gt;
And no, I am aware of searching the _internal for license events, the problem is Splunk have provided broken functionality.&lt;/P&gt;

&lt;P&gt;Any help appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355659#M21303</guid>
      <dc:creator>michael_bates_1</dc:creator>
      <dc:date>2020-09-29T14:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Built-in License Alert broken</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355660#M21304</link>
      <description>&lt;P&gt;Open a support case; this is clearly a bug.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 15:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355660#M21304</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-16T15:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Built-in License Alert broken</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355661#M21305</link>
      <description>&lt;P&gt;The /services/licenser/pools API endpoint is there in order to access the licenser pools configuration and in Splunk Cloud we do not support license pools as described here: &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Service/SplunkCloudservice" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Service/SplunkCloudservice&lt;/A&gt; (" License pooling: You cannot use license pooling in Splunk Cloud").&lt;BR /&gt;
To alert on license usage in Splunk Cloud use index=_internal source=&lt;EM&gt;license_usage.log&lt;/EM&gt; type="RolloverSummary" etc...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355661#M21305</guid>
      <dc:creator>ytenenbaum_splu</dc:creator>
      <dc:date>2020-09-29T14:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Built-in License Alert broken</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355662#M21306</link>
      <description>&lt;P&gt;These alerts are now removed in version 7.0.1 which will be released in the future&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 18:50:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Built-in-License-Alert-broken/m-p/355662#M21306</guid>
      <dc:creator>ytenenbaum_splu</dc:creator>
      <dc:date>2017-11-09T18:50:14Z</dc:date>
    </item>
  </channel>
</rss>

