Deployment Architecture

unable to distribute to peer duplicate license hashes

sonicZ
Contributor

We received an error from our main search head(splunk1) when one of our indexers port 8089 connection was blocked to the license master.

Error screen shot is attached.

Unable to distribute to peer named splunk72-g2-inf at uri https://x.x.x.x because peer as status  = 'duplicate license'. duplicate license hashes: 

....long list of all the hashes.... 

Also present on the search  head(splunk1.xxx.xxx.com)**

It appears that splunk search was disabled and dashboards were not coming up when this one indexer lost connection to the license master. I assumed that only that searches on that indexer would be disabled. Any ideas why this happened?

We currently just have a production pool with all the indexers, and search heads assigned to a single pool.

0 Karma

mwhite_splunk
Splunk Employee
Splunk Employee

It appears the search head was trying to take over as the license master, maybe due to a loss of connectivity. I would ensure that the search head in question is a slave to the license master.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurealicenseslave

sowings
Splunk Employee
Splunk Employee

I've seen situations before where the licensing connection went wonky, and my (quick and dirty) solution was to take the indexer out of the pool, then add it back. YMMV.

sonicZ
Contributor

Hi, well our license master shows the search head has been in the pool. Checking the search head licensing info definitely shows it as a slave to the master.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...