Getting Data In

1MB Forwarder license expiring?

Jason
Motivator

At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where this came from - was this a bug?

user@host $ bin/splunk show license
Current Daily Usage Amount:     0
Expiration date:                2011-03-08T01:07:37-0500
Expiration State:               7
License level:                  1 MB
Product:                        Enterprise
License violations:
Max Violations:
Peak usage:                     0 MB
Days remaining:                 6 day(s)
Violation Period:
Tags (2)
1 Solution

Ellen
Splunk Employee
Splunk Employee

Ellen
Splunk Employee
Splunk Employee

This is a known issue. More details and options can be found here:
http://answers.splunk.com/questions/12167/why-is-the-license-on-the-forwarder-search-head-displaying...

Jason
Motivator

Thanks - This link actually has a copy of the correct license for folks out there. Good to know it's a known bug.

0 Karma

yannK
Splunk Employee
Splunk Employee

A simple solution is to download a splunk 4.1.7 zip/tar.gz and use the forwarder license shipped in it /etc/splunk-forwarder.license

But at this step, why not upgrade directly to 4.1.7

Jason
Motivator

Upgrading will not change the license by default.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This was a bug in one of the releases. You should be able to replace it with the forwarder license from a current release of Splunk. Note that this is mostly of no consequence on a forwarder, since the results of a license lockout are that you can't search, and there is (or should be) nothing to search on a forwarder.

0 Karma

Jason
Motivator

But for other non-indexing uses, such as on a search head, it is of vital importance.

0 Karma

David
Splunk Employee
Splunk Employee

There was a Splunk Answers a bit ago that said they accidentally shipped a bad forwarder.license in one release. It was a bit scant on details, so it's hard to confirm that it is your issue, but it certainly sounds like it.

http://answers.splunk.com/questions/11192/splunk-forwarder-license

Jason
Motivator

More details (and proper license) in #12167.

0 Karma

Jason
Motivator

The expiring license file starts with forwarder@splunk.com and the encrypted text began with RV7. When the license was changed to splunk-forwarder.license from the 4.1.6 64-bit linux tgz package, the date went back to 2020-06-08 as expected (that file starts with forwarder@splunk.com and the encrypted text starts with JbX).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...