Hi 🙂
Dears, I am using Splunk 6.4 as a heavy forwarder which send its logs to an indexer (6.3) .
Heavy forwarder has MySQL add-on installed on it. While trying to search indexed data, I got the error below that my license expired or has been violated, despite still having not indexed any data or expiration date hasn't come!
please advise ?
Thanks
The heavy forwarder should be added as license slave to your actual license master server. Use any of below method to update the same
http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/LicenserCLIcommands#Managing_license_slaves
http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Configurealicenseslave
Remember that licenses are not ONLY about how much data you index per day. The Enterprise license also conveys capabilities, such as distributed search. That's why you need to follow @somesoni2's suggestion.