Getting Data In

How to set up a license for a Heavy Forwarder that is also a Deployment Server?

andrewdidone
Path Finder

Hi.

I have an Indexer/SearchHead/Deploy server sitting on one zone, and a Heavy Forwarder/Deploy server sitting on another zone. Currently my license installed on the Indexer. Since the Heavy Forwarder is a Deployment Server, i am unable to use a free or forwarder license. How would i set up licensing here? Would i configure the forwarder as a slave and point it to the Indexer?

I've tried this and I receive the following error:

Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip='  

Does this mean i need a specific license that allows a slave connection?

Thanks,
Andrew

1 Solution

andrewdidone
Path Finder

Answering my own here. The answer is Yes. You set it up as a slave. My license was just an invalid one. After a proper license install, it seems to work fine now.

Hope this helps anyone else.

View solution in original post

nickstone
Path Finder

anyone know how this works with Splunk Cloud? or is it the same? Just point at Splunk Cloud as License Server?

0 Karma

andrewdidone
Path Finder

Answering my own here. The answer is Yes. You set it up as a slave. My license was just an invalid one. After a proper license install, it seems to work fine now.

Hope this helps anyone else.

napomokoetle
Communicator

Do you know if a pure Heavy Forwarder with NO deployment function and NO local indexing require a license? Or is it taken just like a Universal Forwarder?

0 Karma

lakshman239
SplunkTrust
SplunkTrust
0 Karma

andrewdidone
Path Finder

If there is no deploy server functionality, and no indexing then i believe no license required. it'll just act as a relay. You just need to set up forwarding to the main indexer. Standard port is 9997.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...