Getting Data In

Splunk 5 and search indexers

asarolkar
Builder

Hi,

We were using a system which has a central Splunk head and multiple search peers where the search peers were DISABLED.

Is it possible that an upgrade to Splunk 5 re-enabled them ?

I went to Splunk Manager -> Licensing -> Enterprise license group and I see that ALL MY SEARCH PEERS AS WELL AS MY SEARCH HEAD are using up daily volume.

I doubt that that is the case (that an upgrade can re-activate configuration), but is it actually possible for something like this to happen ?

0 Karma

yannK
Splunk Employee
Splunk Employee

if the search was disabled for any license issue, you need a reset key to unlock the search.
If you have a support contract, file a ticket, otherwise, wait for 30 days for the automatic unlock.

0 Karma

ksusia
New Member

thanks!!!!!!
i got solved problem for you!!!!

0 Karma

asarolkar
Builder

Hi there,

I phrased my question correctly now !

0 Karma

Ayn
Legend

Not an answer, but a sidenote - I think you're confusing search heads and search peers here. A search head performs searches on search peers (peers are typically indexers).