Deployment Architecture

unable to distribute to peer duplicate license hashes

sonicZ
Contributor

We received an error from our main search head(splunk1) when one of our indexers port 8089 connection was blocked to the license master.

Error screen shot is attached.

Unable to distribute to peer named splunk72-g2-inf at uri https://x.x.x.x because peer as status  = 'duplicate license'. duplicate license hashes: 

....long list of all the hashes.... 

Also present on the search  head(splunk1.xxx.xxx.com)**

It appears that splunk search was disabled and dashboards were not coming up when this one indexer lost connection to the license master. I assumed that only that searches on that indexer would be disabled. Any ideas why this happened?

We currently just have a production pool with all the indexers, and search heads assigned to a single pool.

0 Karma

mwhite_splunk
Splunk Employee
Splunk Employee

It appears the search head was trying to take over as the license master, maybe due to a loss of connectivity. I would ensure that the search head in question is a slave to the license master.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurealicenseslave

sowings
Splunk Employee
Splunk Employee

I've seen situations before where the licensing connection went wonky, and my (quick and dirty) solution was to take the indexer out of the pool, then add it back. YMMV.

sonicZ
Contributor

Hi, well our license master shows the search head has been in the pool. Checking the search head licensing info definitely shows it as a slave to the master.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...