Deployment Architecture

Multiple warning which lead to License Violation for a Slave

Dark_Ichigo
Builder

Im getting this warning only one one of my Slave license servers which has its own License pool:

slave had no matching license for data it indexed

I dont know what its telling me here?

0 Karma

linu1988
Champion

Hello Ichigo,
Use the Deployment monitor app to see the error and remove the source/ source type as soon as possible. This will lead to violation of the error for the whole license. Pool license means all the servers included on the pool not any individual. I am sure that is some bad definition/some data is there which Splunk doesn't like ;). Thanks.

0 Karma

linu1988
Champion

No, you can see for yourself the pool would be having the license available still. Splunk does show up violation error with incompatible sourcetype/source. Kindly contact support team if you are not sure about this. But Deployment monitor app will help you resolving this error as it shows from where it's coming..

0 Karma

Dark_Ichigo
Builder

So technically it's not related to insufficient Volume license to that specific pool where the warning issue currently lyes?

0 Karma

lukejadamec
Super Champion

The master license server has not allocated sufficent volume to the slave.
http://docs.splunk.com/Documentation/Splunk/5.0.4/Admin/Groups,stacks,pools,andotherterminology#Lice...

Dark_Ichigo
Builder

I reset the license and increased the Pool size....I'll see if this is indeed the issue

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...