Getting Data In

1MB Forwarder license expiring?

Jason
Motivator

At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where this came from - was this a bug?

user@host $ bin/splunk show license
Current Daily Usage Amount:     0
Expiration date:                2011-03-08T01:07:37-0500
Expiration State:               7
License level:                  1 MB
Product:                        Enterprise
License violations:
Max Violations:
Peak usage:                     0 MB
Days remaining:                 6 day(s)
Violation Period:
Tags (2)
1 Solution

Ellen
Splunk Employee
Splunk Employee

Ellen
Splunk Employee
Splunk Employee

This is a known issue. More details and options can be found here:
http://answers.splunk.com/questions/12167/why-is-the-license-on-the-forwarder-search-head-displaying...

Jason
Motivator

Thanks - This link actually has a copy of the correct license for folks out there. Good to know it's a known bug.

0 Karma

yannK
Splunk Employee
Splunk Employee

A simple solution is to download a splunk 4.1.7 zip/tar.gz and use the forwarder license shipped in it /etc/splunk-forwarder.license

But at this step, why not upgrade directly to 4.1.7

Jason
Motivator

Upgrading will not change the license by default.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This was a bug in one of the releases. You should be able to replace it with the forwarder license from a current release of Splunk. Note that this is mostly of no consequence on a forwarder, since the results of a license lockout are that you can't search, and there is (or should be) nothing to search on a forwarder.

0 Karma

Jason
Motivator

But for other non-indexing uses, such as on a search head, it is of vital importance.

0 Karma

David
Splunk Employee
Splunk Employee

There was a Splunk Answers a bit ago that said they accidentally shipped a bad forwarder.license in one release. It was a bit scant on details, so it's hard to confirm that it is your issue, but it certainly sounds like it.

http://answers.splunk.com/questions/11192/splunk-forwarder-license

Jason
Motivator

More details (and proper license) in #12167.

0 Karma

Jason
Motivator

The expiring license file starts with [email protected] and the encrypted text began with RV7. When the license was changed to splunk-forwarder.license from the 4.1.6 64-bit linux tgz package, the date went back to 2020-06-08 as expected (that file starts with [email protected] and the encrypted text starts with JbX).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...