Deployment Architecture

Multiple warning which lead to License Violation for a Slave

Dark_Ichigo
Builder

Im getting this warning only one one of my Slave license servers which has its own License pool:

slave had no matching license for data it indexed

I dont know what its telling me here?

0 Karma

linu1988
Champion

Hello Ichigo,
Use the Deployment monitor app to see the error and remove the source/ source type as soon as possible. This will lead to violation of the error for the whole license. Pool license means all the servers included on the pool not any individual. I am sure that is some bad definition/some data is there which Splunk doesn't like ;). Thanks.

0 Karma

linu1988
Champion

No, you can see for yourself the pool would be having the license available still. Splunk does show up violation error with incompatible sourcetype/source. Kindly contact support team if you are not sure about this. But Deployment monitor app will help you resolving this error as it shows from where it's coming..

0 Karma

Dark_Ichigo
Builder

So technically it's not related to insufficient Volume license to that specific pool where the warning issue currently lyes?

0 Karma

lukejadamec
Super Champion

The master license server has not allocated sufficent volume to the slave.
http://docs.splunk.com/Documentation/Splunk/5.0.4/Admin/Groups,stacks,pools,andotherterminology#Lice...

Dark_Ichigo
Builder

I reset the license and increased the Pool size....I'll see if this is indeed the issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...