Deployment Architecture

Is it possible to use the Splunk Cloud license master for on-prem Heavy Forwarders?

konstr
Path Finder

I'm deploying an on-prem architecture consisting of a deployment server and a number of Heavy Forwarders forwarding data into Splunk Cloud. The on-prem components are only forwarding and not indexing.

I was wondering if it is possible to have all of the on-prem Splunk instances (DS and HFs) act as license slaves to the splunk cloud license master. And how to do that? I tried pointing them to the Splunk cloud license master but the connection times out. There isn't clear documentation on if this is possible.

I am aware that since the HFs aren't indexing I could use a forwarder license and for the DS request a 0MB license from splunk. However, connecting them to the Splunk Cloud license master seems more future proof, and allows for expansion and possible changes in the future, including "forward and indexing".

1 Solution

amiracle
Splunk Employee
Splunk Employee

We do not offer the ability to connect to the splunk cloud license master. The two options you have are 1) get the 1mb license from support to install in your on-Prem splunk servers (HF’s, SH’s, DS, etc.) 2) get the dev license if you want to test sources in your own splunk deployment (dev.splunk.com).

View solution in original post

amiracle
Splunk Employee
Splunk Employee

We do not offer the ability to connect to the splunk cloud license master. The two options you have are 1) get the 1mb license from support to install in your on-Prem splunk servers (HF’s, SH’s, DS, etc.) 2) get the dev license if you want to test sources in your own splunk deployment (dev.splunk.com).

abk_hex
Loves-to-Learn Lots

@amiracle  I have a question out of this, do i have to use the 0Mb license separately on all the server like HF and DS. Or I can make DS as license master and point HF towards it. 

as I did make DS as license master and point HF towards it., but still not seeing logs from HF to cloud

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...