Deployment Architecture

licensing in a distributed deployment

brettcave
Builder

we've recently migrated to a distributed deployment, with a licensing server. a recent surge in events caused licensing to be exceeded, and we received a reset license which was installed on the license master. however, we still cant search on the shc due to licensing errors.

after installing a license on the master, what is needed to enable searching across the cluster?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You must point all your servers to use that same license master. More info how to do it can found from here: https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/Distdeploylicenses.

In some cases there have been an issue with old perpetual licenses and then you should create a case to Splunk support.

R. Ismo

0 Karma

codebuilder
Influencer

You need to configure your search heads to be license slaves, and point them to the license master.

Settings > Licensing > Change to Slave > Designate a different Splunk instance as the master license server

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

You'll need to do the same for your indexers btw, if you haven't already.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

Did this help you resolve your issue? if so, please "accept" the answer so that others in the community may benefit.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...