<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: License violation on forwarders? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23342#M9180</link>
    <description>&lt;P&gt;is it at all possible that your indexer's licensing configuration allows it to accept connections from any indexers by default? by default, this is how the licenser is configured, from &lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Createalicensepool" target="_blank"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Createalicensepool&lt;/A&gt; : &lt;/P&gt;

&lt;P&gt;"When you install an Enterprise license onto a brand new Splunk server, Splunk automatically creates an Enterprise license stack called Splunk Enterprise Stack from it and defines a default license pool for it called auto_generated_pool_enterprise.&lt;/P&gt;

&lt;P&gt;The default configuration for this default pool adds any license slave that connects to this license master to the pool. You can edit the pool to change this configuration, to add more indexers to it, or create a new license pool from this stack."&lt;/P&gt;

&lt;P&gt;it seems like a long shot, but perhaps there are other indexers at your organization connecting as license slaves to your indexer?&lt;/P&gt;

&lt;P&gt;another possibility is that you are using deployment server and that every time it restarts its deployment clients (the forwarders), they report into the indexer as a new license slave? &lt;/P&gt;

&lt;P&gt;all very speculative, i'm afraid. i recommend submitting a case to Splunk Support. &lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:39:04 GMT</pubDate>
    <dc:creator>piebob</dc:creator>
    <dc:date>2020-09-28T09:39:04Z</dc:date>
    <item>
      <title>License violation on forwarders?</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23341#M9179</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;According to the splunk interface I have a warning:&lt;BR /&gt;
"1 pool violation reported by 1 indexer" &lt;BR /&gt;
Details:&lt;BR /&gt;
"This pool contains 173 slave/s in violation"&lt;/P&gt;

&lt;P&gt;Firstly, many of these are heavy forwarders, but some are light.&lt;BR /&gt;
Also, I don't have any slave indexers (on purpose?) and I don't have 173 of anything.&lt;/P&gt;

&lt;P&gt;Obviously, I am confused about something.  &lt;/P&gt;

&lt;P&gt;I have one splunk indexer, and &lt;EM&gt;maybe&lt;/EM&gt; a dozen forwarders/heavy forwarders.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2011 19:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23341#M9179</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-06-06T19:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: License violation on forwarders?</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23342#M9180</link>
      <description>&lt;P&gt;is it at all possible that your indexer's licensing configuration allows it to accept connections from any indexers by default? by default, this is how the licenser is configured, from &lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Createalicensepool" target="_blank"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Createalicensepool&lt;/A&gt; : &lt;/P&gt;

&lt;P&gt;"When you install an Enterprise license onto a brand new Splunk server, Splunk automatically creates an Enterprise license stack called Splunk Enterprise Stack from it and defines a default license pool for it called auto_generated_pool_enterprise.&lt;/P&gt;

&lt;P&gt;The default configuration for this default pool adds any license slave that connects to this license master to the pool. You can edit the pool to change this configuration, to add more indexers to it, or create a new license pool from this stack."&lt;/P&gt;

&lt;P&gt;it seems like a long shot, but perhaps there are other indexers at your organization connecting as license slaves to your indexer?&lt;/P&gt;

&lt;P&gt;another possibility is that you are using deployment server and that every time it restarts its deployment clients (the forwarders), they report into the indexer as a new license slave? &lt;/P&gt;

&lt;P&gt;all very speculative, i'm afraid. i recommend submitting a case to Splunk Support. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23342#M9180</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2020-09-28T09:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: License violation on forwarders?</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23343#M9181</link>
      <description>&lt;P&gt;Thanks!    Our organization only has the one indexer, and I'm not doing any form of deployment.&lt;/P&gt;

&lt;P&gt;I will submit a case, if possible.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2011 14:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-on-forwarders/m-p/23343#M9181</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-06-08T14:50:44Z</dc:date>
    </item>
  </channel>
</rss>

