Getting Data In

SPLUNK License master down - what is the impact ??

rakesh_498115
Motivator

Hi ,

I have a single license master with 4 indexer servers sharing the license from it. From this morning, my License Master was down, but I can still see Splunk indexing is working and there was no impact to the data.

I was surprised that Splunk can still index all the data to the indexers even though the Master license server is down. If this is the case, then what is the impact? Is there an idle time that Splunk stops indexing data until the master is up and running again?

Do we need to change the Master since the existing server is down? Can someone help me here pls?

thanks,
Rakesh.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

View solution in original post

surajkuvar
New Member

@esix[Splunk] What happens when License master is down. Does it count for indexing when it was down?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...