Installation

Is ITSI license limited on the number of SH's it will authorize?

csprice
Path Finder

We have an ITSI instance with a 4 member SHC and a 4 member indexer cluster.

Every day one of the SHC members complains that it doesn't have a valid ITSI license. Restarting splunk seems to cause this error to go away but move to a different SHC member.

Looking in the itsi_license_checker.log across all 4 instances, you can see the error travel between the server with one and only one instance complaining that the "Splunk instance does not have a valid license for IT Service Intelligence."

Checking the license master - both the Splunk Enterprise and Splunk ITSI Perpetual licenses show up and have an expiration of more than 20 years from now.

Any thoughts on why this is happening?

Labels (3)
0 Karma

mdonnelly_splun
Splunk Employee
Splunk Employee

I realize this is an old request but people keep seeking information related to the title of this post ...

ITSI is only licensed by data volumes from the indexers.

None of the following are controlled by the ITSI license:

Search heads

Indexers, indexer clusters

users

KPIs, glass tables, services, entities

As to the cause of the problem in your post...

* Verify that each search head is configured for the license master
* Verify KV Store replication status

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You shouldn't be getting a license error on a SH member since the data lives on the indexers. Is your SH members connected to the license master? Are they acting as a license master?

0 Karma

csprice
Path Finder

They are connected to the license master.

0 Karma

csprice
Path Finder

Also, it's not a license violation - it's an invalid license warning on just one instance that hops from shc member to shc member.

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...