Getting Data In

Can I enable distributed indexer using Enterprise Trial license ?

manojgeorge007
New Member

Hi - I am using Splunk Enterprise Trial license at home network for learning purpose.

I have installed Splunk(Linux) on my two machines within home network.
When I try to change the license configuration to Slave in one of the machine to make one as master and another as slave, it gives below error..

"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip="

As per documentation, distributed indexing is possible with Splunk Enterprise Trial license. Am I missing something?
Pls advise.

Thanks ,
Manoj

Tags (2)
0 Karma
1 Solution

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

View solution in original post

0 Karma

deejaybags
Engager

You could also request a splunk dev license. It will allow you to do the funky stuff like index clustering and search head clustering, and allows you to index 10G/day. It is great for home/lab set-ups like you describe you have.

0 Karma

raghu0463
Explorer

How to request a dev license please.

0 Karma

MuS
Legend

Hi raghu0363,

start here http://dev.splunk.com/page/developer_license_sign_up

cheers, MuS

0 Karma

neelamssantosh
Contributor

Hi Manoj,

Unfortunately, No is the answer.

Respective features are not available in Trail/Free.
Hope, Below link can help you better.
http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

All the best and Keep splunking.

0 Karma

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

0 Karma

manojgeorge007
New Member

Thank You Raghav , Neelam. Your response helps.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...