Security

license error in trail version of splunk

Prakhar_shukla
Path Finder

Hello,
we have 3 indexer, 1 search head and a cluster master in our current set up. we are seeing following error for all 3 indexer -

Search peer abc.com has the following message: Failed to contact license master: reason='WARN: path=/masterlm/usage: invalid signature on request from ip=' first failure time=1490587494 (Mon Mar 27 06:04:54 2017)

Error in search head - for all 3 indexer
[abc.com] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_GRACE_PERIOD,0])

Streamed search execute failed because: Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

as we are suing trial version, so all instances are acting as standalone license server. please helpout in fixing the issue

Tags (1)
0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

How long have you been using your trial license for?

After 60 days, it rolls into a free license which disables distributed searching. You should also go look at how much data you've indexed by going to Settings > Licenses

If you dont have a license master you will have to do this on all 3 of your indexers

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

How long have you been using your trial license for?

After 60 days, it rolls into a free license which disables distributed searching. You should also go look at how much data you've indexed by going to Settings > Licenses

If you dont have a license master you will have to do this on all 3 of your indexers

0 Karma

Prakhar_shukla
Path Finder

hi skoelpin,

its been 2 week only i installed enterprise trial version. i have sufficient validity.however i am wondering to this error "you have exceeded your license limit too many times."
is it possible if my indexers indexed too much data during weekend, because it was working fine on friday.
can you help me out a way to check how much data indexer indexed, web page is not able on indexer?
is there any setting by which i can limit the indexing done by indexers per day. my daily quota is 250 MB.

0 Karma

Prakhar_shukla
Path Finder

somehow my license usage have no value in any of indexer. i am not sure why
however, i reinstalled enterprise trial version on all indexer and able to work for now. hopefully wont have similar problem again.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yeah the indexers have Splunk web enabled by default so you can login to the Indexer GUI and see the indexing amount.

Open a web browser and navigate to your indexer IP with port 8000 IP:8000and login. Once logged in you can go to Settings > Licenses and you can view 30 days worth of data indexed. You have to login to all 3 indexers since you do not have a license master

Do you have the forwarders load balancing to the each indexer? I'm betting more data is being sent to one indexer than the rest which is causing you to get that error. If you exceed 5 days of overages in a 30 day period then you will see that error

You should also have 500MB/day indexing available during a trial period

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Prakhar_shukla,
there could be a communication problem between the indexing nodes and the license server, like the one described in https://answers.splunk.com/answers/93699/disabled-due-to-grace-period.html
Or you have exceeded your license limit too many times: the trial version can index 500 MB/day and are possible only two violation before the block of searches.

In first case verify your network.
In the second case go in [Settings -- Licensing] of your License Master and verify if you're in violation.

Bye.
Giuseppe

0 Karma

Prakhar_shukla
Path Finder

but i am using free enterprise version which means all splunk instances are acting as license master for themself.

there is no violation

Current

No licensing alerts

Permanent

No licensing violations

and here usage is -

Licensed daily volume 500 MB

Volume used today 0 MB (0% of quota)

Warning count 0

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...