Getting Data In

SPLUNK License master down - what is the impact ??

rakesh_498115
Motivator

Hi ,

I have a single license master with 4 indexer servers sharing the license from it. From this morning, my License Master was down, but I can still see Splunk indexing is working and there was no impact to the data.

I was surprised that Splunk can still index all the data to the indexers even though the Master license server is down. If this is the case, then what is the impact? Is there an idle time that Splunk stops indexing data until the master is up and running again?

Do we need to change the Master since the existing server is down? Can someone help me here pls?

thanks,
Rakesh.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

View solution in original post

surajkuvar
New Member

@esix[Splunk] What happens when License master is down. Does it count for indexing when it was down?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...