Deployment Architecture

Why did a license slave indexer receive a license violation when the indexing volume is still less than the license volume limit.

Masa
Splunk Employee
Splunk Employee

I have 20GB license in my license master. And, I made an indexer as a license slave to the master.
The indexer indexes about 1GB daily.

Since I made the indexer license slave, I receive license violation warning every day. The license pool volume usage is about 13GB every day. Why did I receive license violation for the indexer every day?

1 Solution

Masa
Splunk Employee
Splunk Employee

Please check the license master's Manager --> Licensing, and make sure you see the slave in the pool while you can see other indexers under the pool.

If not, please click "Edit" of the license pool and see if the indexer is assigned to the pool. If you have set the pool to "Specific Indexers", not "Any Indexer that connects", you have to assign the slave indexer to the pool manually.

So, if the slave did not belong to any pool, the slave was entitled to zero volume license. As a result, the slave indexer received a license violation every day.

Or, if the license slave was disconnected over 24 hours, the indexer will get a license violation. In that case, you can find a warning message in the slave indexer's splunkd.log.

View solution in original post

Masa
Splunk Employee
Splunk Employee

Please check the license master's Manager --> Licensing, and make sure you see the slave in the pool while you can see other indexers under the pool.

If not, please click "Edit" of the license pool and see if the indexer is assigned to the pool. If you have set the pool to "Specific Indexers", not "Any Indexer that connects", you have to assign the slave indexer to the pool manually.

So, if the slave did not belong to any pool, the slave was entitled to zero volume license. As a result, the slave indexer received a license violation every day.

Or, if the license slave was disconnected over 24 hours, the indexer will get a license violation. In that case, you can find a warning message in the slave indexer's splunkd.log.

Get Updates on the Splunk Community!

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...