Getting Data In

Can I enable distributed indexer using Enterprise Trial license ?

manojgeorge007
New Member

Hi - I am using Splunk Enterprise Trial license at home network for learning purpose.

I have installed Splunk(Linux) on my two machines within home network.
When I try to change the license configuration to Slave in one of the machine to make one as master and another as slave, it gives below error..

"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip="

As per documentation, distributed indexing is possible with Splunk Enterprise Trial license. Am I missing something?
Pls advise.

Thanks ,
Manoj

Tags (2)
0 Karma
1 Solution

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

View solution in original post

0 Karma

deejaybags
Engager

You could also request a splunk dev license. It will allow you to do the funky stuff like index clustering and search head clustering, and allows you to index 10G/day. It is great for home/lab set-ups like you describe you have.

0 Karma

raghu0463
Explorer

How to request a dev license please.

0 Karma

MuS
Legend

Hi raghu0363,

start here http://dev.splunk.com/page/developer_license_sign_up

cheers, MuS

0 Karma

neelamssantosh
Contributor

Hi Manoj,

Unfortunately, No is the answer.

Respective features are not available in Trail/Free.
Hope, Below link can help you better.
http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

All the best and Keep splunking.

0 Karma

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

0 Karma

manojgeorge007
New Member

Thank You Raghav , Neelam. Your response helps.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...