Getting Data In

Splunk 5 and search indexers



We were using a system which has a central Splunk head and multiple search peers where the search peers were DISABLED.

Is it possible that an upgrade to Splunk 5 re-enabled them ?

I went to Splunk Manager -> Licensing -> Enterprise license group and I see that ALL MY SEARCH PEERS AS WELL AS MY SEARCH HEAD are using up daily volume.

I doubt that that is the case (that an upgrade can re-activate configuration), but is it actually possible for something like this to happen ?

0 Karma

Splunk Employee
Splunk Employee

if the search was disabled for any license issue, you need a reset key to unlock the search.
If you have a support contract, file a ticket, otherwise, wait for 30 days for the automatic unlock.

0 Karma

New Member

i got solved problem for you!!!!

0 Karma


Hi there,

I phrased my question correctly now !

0 Karma


Not an answer, but a sidenote - I think you're confusing search heads and search peers here. A search head performs searches on search peers (peers are typically indexers).

Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Hi Splunky people! We are excited to share the newest updates in Splunk Enterprise 9.3!Admins and Analyst can ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...