Hello there,
I'm trying to install this addon on a distributed environment. I installed on the Heavy Forwarder as specified, and on the search heads.
I deployed with deployment server, and here is the log I get in the ta_ms_o365_message_trace.log on the HF :
HTTPError : HTTP 402 Payment Required -- Requires license feature='KVStore'
My question is : is there any workaround or did I something wrong to install ?
FYI, I installed on a standalone Splunk server and didn't have any issue.
My HF is version 6.5.2.
Best regards, and hope someone will help 🙂
I had the same issue running this add-on on my Heavy Forwarder. I realized that I hadn't added the Heavy Forwarder as a license slave. After configuring the Heavy Forwarder as a license slave and restarting, the add-on worked.
http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Configurealicenseslave
I had the same issue running this add-on on my Heavy Forwarder. I realized that I hadn't added the Heavy Forwarder as a license slave. After configuring the Heavy Forwarder as a license slave and restarting, the add-on worked.
http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Configurealicenseslave
Thanks, I no longer have the message !
And thanks for your very quick answer too.
Best regards.
I am having the same issue as above but my HFW has the basic splunkforwarder license as we do not do any indexing on it.
Therefore my questions is:
How do I do this change on a HFW with standard forwarder license which doesn't require a license master.
Maybe you can add the machine indexing the data. You should have one at least ?
And then put your HFW as a slave of this machine.
Nope...Splunk Cloud Customer!!
The fix is to raise a call with Splunk to provide 0GB ingestion license that still enables the KVStore.
They also have to do this with Deployment Servers if you are a Splunk Cloud user.
The only weird thing is that in the btool server list shows KVStore being enabled but I guess it still has to be allowed in the license, which it is NOT in the UF license.
Yeah but you con't install this addon on a UF, it is still dedicated to the HF.
I know you can't use it on UF, we deploy it on a HFW which is technically only a UF in the fact that is is only used to parse & forward, NOT index.
In a Splunk Cloud scenario, where your License Master, indexers & SH's are in the cloud, you don't use license slaves and the HFW that are used for parsing and add-ons that require it, usually just have a SplunkForwader license installed as there is no need for LM at this point. To stop the requirement for license master on-prem Splunk will provide, when requested a 0Gb license so that all features are allowed, except for indexing! You have to do this also for the Deployment Server or you lose the Deployment Server functions.
Just to advise that my original fix comment worked and Splunk provided the required license which allowed me to move on but now have weird SSL errors which are discussed on https://answers.splunk.com/answers/582779/sslerror-ssl-certificate-verify-failed-certificate.html#co... if you would like to assist with that too?