Getting Data In

SPLUNK License master down - what is the impact ??

rakesh_498115
Motivator

Hi ,

I have a single license master with 4 indexer servers sharing the license from it. From this morning, my License Master was down, but I can still see Splunk indexing is working and there was no impact to the data.

I was surprised that Splunk can still index all the data to the indexers even though the Master license server is down. If this is the case, then what is the impact? Is there an idle time that Splunk stops indexing data until the master is up and running again?

Do we need to change the Master since the existing server is down? Can someone help me here pls?

thanks,
Rakesh.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

View solution in original post

surajkuvar
New Member

@esix[Splunk] What happens when License master is down. Does it count for indexing when it was down?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will have 72 hours from the License Master going down till when Search becomes unavailable. Your indexing will still work, you just wont be able search the data.

Read this : http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Aboutlicenseviolations

So you need to restore / rebuild the license master as soon as possible.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...