Installation

How to add license slave in server.conf in apps?

emallinger
Communicator

Hello,

I'm currently installing and configuring a new monitoring console. I've another instance which is License Master.

I'm doing configuration with conf files.

On my new MC, I've added in /opt/splunk/apps/my_app/local/server.conf

[license]

master_uri = https://xx.XX.XX.XX:8089

Flux are opened. Master_uri is up.

On the new instance `Btool server list license --debug` shows only this file applyied :

/opt/splunk/etc/system/default/server.conf

I don't understand what I'm doing wrong.

Any pointers ?

Thanks a lot !

Ema

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

splunk btool reads from disk, not from running process, for that reason no restart is needed.

Are you sure that user has read access to that file? And you are using correct /opt/splunk/bin/splunk command with correct env variables if those are defined?

r. Ismo 

View solution in original post

emallinger
Communicator

Hi,

Thanks !!

There was an error in file owner ! Goog suggestion ! I'm waiting for the result of that change. If lucky, I'll check your post as a solution. If not, I'll tell.

Regards,

Ema

0 Karma

emallinger
Communicator

Ow !

I didn't put any pass4Symmkey in the file (there was none in any of my other search-head, only on the Cluster Master (also License Mater) and all the indexers from the Indexer Cluster).

Here's the outputs.conf :

[indexAndForward]
index = false

[tcpout] :
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = xx1:9997,xx2:9997,xx3:9997
autoLB = true

 

What's to do with License ?

Thanks,

Ema

0 Karma

emallinger
Communicator

Hello,

Yes, I restarted it, twice ;-). No change.

I put my conf file in item 3 of precedence order, so in theory it should work.

I must be missing something, somewhere...

Thanks in advance for any suggestion.

Ema

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @emallinger 

Can you share the output of server.conf in app local directory

and pass4SymmKey  should be same in for License master, and other compoenets connecting to it 
[general]
pass4SymmKey=<valueinplaintext> and post restart it will be encrypted 

I would suggest take new pass4SymmKey value and update in all componetts connwecting to license master  and restart Splunkd 

and run /opt/splunk/bin/splunk btool server list --debug

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @emallinger 

Stupid question from my side

have you restarted the splunk after changes in server.conf?. if not can you restart splunk and run btool command 

 as per config file percendence /etc/system/default/ has lowest precendence,

below is the priority from higest to lowest 

 

  1. etc/system/local
  2. etc/apps/search/local
  3. etc/apps/<appname>/local
  4. etc/apps/search/deafult/
  5. etc/apps/<appname>/default
  6. etc/system/default
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

splunk btool reads from disk, not from running process, for that reason no restart is needed.

Are you sure that user has read access to that file? And you are using correct /opt/splunk/bin/splunk command with correct env variables if those are defined?

r. Ismo 

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...