Installation

How to resolve overreporting of license usage after temporary storage issue?

devinmclean
Path Finder

Our license server ran into a space issue where we ran under 1,000 MB of space available. Therefore, it stopped indexing. This went unnoticed for a few days, and it fixed itself for a day or two, and then went back under 1,000 MB again. This causes the license measurements to go completely off the charts. For example, our indexers are only consuming about 500 GB all together right now, but the license server things we're at 4.5TB. Is there a way to correct the license server's values?

Labels (1)
0 Karma

rafamss
Contributor

Hi @devinmclean,

What is the size of your license? Usually when this happen you will need request a support for your Splunk team to fix your license.
Other thing to do is analysis how is the offender of this sudden increase and in some cases, disable the collect of data for a while for to do this.

I hope help you.

[ ]s
Rafael Martins

0 Karma

devinmclean
Path Finder

Hey @rafamss,

The license is not actually being exceeded. The license server is displaying incorrect information due to it shutting down and not indexing data (caused by the HD on the server being full). I'm wondering if anyone else has seen this kind of behavior and how to fix it.

0 Karma

rafamss
Contributor

Sure @devinmclean,

I've never passed for any similar event like your, but try this tips, I hope this help you.

By the way, did you look the log of license master? $SPLUNK_HOME/var/log/splunk/license_usage.log to find any anomalous event?

A workarround would be delete the licenses of your environment and put this again.

There is some know issues and workarrounds of Splunk 7.0 release notes, see this: http://docs.splunk.com/Documentation/Splunk/7.0.0/ReleaseNotes/Knownissues

[ ]s
Rafael Martins

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...