Getting Data In

Why am I getting an error that my license has expired or have exceeded license violations?

abdallah_hegazy
Explorer

Hi 🙂

Dears, I am using Splunk 6.4 as a heavy forwarder which send its logs to an indexer (6.3) .
Heavy forwarder has MySQL add-on installed on it. While trying to search indexed data, I got the error below that my license expired or has been violated, despite still having not indexed any data or expiration date hasn't come!

please advise ?
alt text

alt text

Thanks

0 Karma

somesoni2
Revered Legend

The heavy forwarder should be added as license slave to your actual license master server. Use any of below method to update the same

http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/LicenserCLIcommands#Managing_license_slaves
http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Configurealicenseslave

0 Karma

lguinn2
Legend

Remember that licenses are not ONLY about how much data you index per day. The Enterprise license also conveys capabilities, such as distributed search. That's why you need to follow @somesoni2's suggestion.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...