Installation

How do I remove expired Splunk Light licenses and still preserve my license pool?

kiles
Explorer

After a year of using Splunk Light I have four different licenses listed under Licensing in Splunk Web. Two have expired, one is a temporary Splunk Light Trial applied while waiting for a new license renewal, and the final is the actual renewal for one year. The Licensing page also shows a couple of alerts ...

This pool has exceeded its configured poolsize=0 bytes. A warning has been recorded for all members
This pool contains slave(s) with 1 warning(s)

Both the Splunk Light Trial and the Splunk Light Term are currently active giving me a total of 10Gb/day but the trial will expire on 6-30-2017 which should put me back to the 5Gb/day that I purchased.

How do I clean up these licenses in Splunk Light (no Splunk Web option to delete a license like in Enterprise) without creating issues with the license pool? There are no slaves and this is a single server configuration.

Labels (1)
0 Karma

kiles
Explorer

I was able to clean this up using the CLI (reference https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/LicenserCLIcommands).

  1. Logged into the Splunk server and ran: splunk list licenses. Captured the HASHES for the expired licenses from the GUI.
  2. Removed the expired license using command: splunk remove licenses HASH. This removed the license immediately from the GUI - no restart required.

I still see four license pools when running the command: splunk list licenser-pools; however, only auto_generated_pool_lite showed used_bytes leading me to believe that was the only active pool. The other three said used_bytes:0.

Running the command : splunk list licenser-messages still shows two messages containing the messages described in the original post. I found no way via the CLI to clean this up.

kiles
Explorer

A bit more information. While the GUI shows only four licenses, the command splunk list licenses shows more (removed HASHES and GUIDs for security reasons).

group_id:Lite
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Light Trial
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:21474836480
max_users:5
max_violations:5
quota:5368709120
relative_expiration_interval:0
relative_expiration_start:0
sourcetypes:
stack_id:lite
status:VALID
subgroup_id:Production
type:lite
window_period:30

group_id:Lite
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Light Term
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:21474836480
max_users:0
max_violations:5
quota:5368709120
relative_expiration_interval:0
relative_expiration_start:0
sourcetypes:
stack_id:lite
status:VALID
subgroup_id:Production
type:lite
window_period:

group_id:Lite_Free
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Light Free
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:529530880
max_users:1
max_violations:5
quota:524288000
relative_expiration_interval:31536000
relative_expiration_start:1494872669
sourcetypes:
stack_id:lite_free
status:VALID
subgroup_id:Production
type:lite_free
window_period:30

group_id:Lite
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Light Download Trial
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:21474836480
max_users:5
max_violations:5
quota:5368709120
relative_expiration_interval:2592000
relative_expiration_start:1494872669
sourcetypes:
stack_id:lite
status:EXPIRED
subgroup_id:Production
type:lite
window_period:30

group_id:Lite
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Light Term
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:21474836480
max_users:0
max_violations:5
quota:5368709120
relative_expiration_interval:0
relative_expiration_start:0
sourcetypes:
stack_id:lite
status:EXPIRED
subgroup_id:Production
type:lite
window_period:30

group_id:Forwarder
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Forwarder
license_hash: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:18446744073709551615
max_users:4294967295
max_violations:5
quota:1048576
relative_expiration_interval:0
relative_expiration_start:0
sourcetypes:
stack_id:forwarder
status:VALID
subgroup_id:Production
type:forwarder
window_period:30

group_id:Free
guid:00000000-0000-0000-0000-000000000000
is_unlimited:0
label:Splunk Free
license_hash:FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
max_stack_quota:18446744073709551615
max_users:4294967295
max_violations:3
quota:524288000
relative_expiration_interval:0
relative_expiration_start:0
sourcetypes:
stack_id:free
status:VALID
subgroup_id:Production
type:free
window_period:30

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...