Getting Data In

Can I enable distributed indexer using Enterprise Trial license ?

manojgeorge007
New Member

Hi - I am using Splunk Enterprise Trial license at home network for learning purpose.

I have installed Splunk(Linux) on my two machines within home network.
When I try to change the license configuration to Slave in one of the machine to make one as master and another as slave, it gives below error..

"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip="

As per documentation, distributed indexing is possible with Splunk Enterprise Trial license. Am I missing something?
Pls advise.

Thanks ,
Manoj

Tags (2)
0 Karma
1 Solution

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

View solution in original post

0 Karma

deejaybags
Engager

You could also request a splunk dev license. It will allow you to do the funky stuff like index clustering and search head clustering, and allows you to index 10G/day. It is great for home/lab set-ups like you describe you have.

0 Karma

raghu0463
Explorer

How to request a dev license please.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi raghu0363,

start here http://dev.splunk.com/page/developer_license_sign_up

cheers, MuS

0 Karma

neelamssantosh
Contributor

Hi Manoj,

Unfortunately, No is the answer.

Respective features are not available in Trail/Free.
Hope, Below link can help you better.
http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

All the best and Keep splunking.

0 Karma

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

0 Karma

manojgeorge007
New Member

Thank You Raghav , Neelam. Your response helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...