Deployment Architecture

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times.

richkappler
Path Finder

Probably the wrong board, choices were limited.
In our dev environment we have a 3 node sh cluster, a 3 node idx cluster, an ES sh and a few other anciliary machines (DS, deployer, UF's HF's, LM, CM, etc). All instances use the one LM. 

On the SHC we are unable to search, getting the subject line message, yet on the ES SH we can search fine and no error message. The nodes of the SHC are "phoning home" to the LM. Licensing settings (indexer name, manager server uri) have been verified as correct. All nodes show having connected to the LM within the last minute-ish.

Not sure where to look from here.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

there should be more information on _internal log. Just query from it like

index=_internal LM* OR expired

That should show you more information about y our issue.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...