Installation

Connection from license slaver to master

splunkreal
Motivator

Hello guys,

is any slunk license slave able to report to a license manager without any authentification or key?

Also from this slave is it possible to connect to the splunk API port (also port tcp:8089) which is not desirable?

Thanks.

* If this helps, please upvote or accept solution 🙂 *
Labels (1)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

in splunk 6.* and recent, the license slave has to share a pass4symmkey with the license-master.
and the license slave instances have to be able to reach license-master on port 8089 (api port)

Make sure that the original pass4symmkey is the same in their server.conf under [general] by default.
(beware, the clear string will be encrypted after a restart, so it may look different across instances, as they encrypt differently)

see http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Serverconf

View solution in original post

yannK
Splunk Employee
Splunk Employee

in splunk 6.* and recent, the license slave has to share a pass4symmkey with the license-master.
and the license slave instances have to be able to reach license-master on port 8089 (api port)

Make sure that the original pass4symmkey is the same in their server.conf under [general] by default.
(beware, the clear string will be encrypted after a restart, so it may look different across instances, as they encrypt differently)

see http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Serverconf

splunkreal
Motivator

Thanks a lot yann, does this require local admin credentials or license master ones?

* If this helps, please upvote or accept solution 🙂 *
0 Karma

yannK
Splunk Employee
Splunk Employee

no, just having unified your pass4symkey
(have having valid ssl certs)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...