Installation

Is it possible to enable License Usage logging on a license slave?

Ant1D
Motivator

Hi,

Is it possible to enable license usage logging on a license slave?

We have a splunk instance that is connected to a remote license master. The remote license master also manages licenses for other Splunk instances that we do not own. We want our license_usage logging available locally as we do not look after or manage the license master. This would be helpful for configuring the Splunk Deployment Monitor App that we have installed on our local instance.

The only events I can see in the license_usage.log are:

LicenseUsage - type=Message - License usage logging not available for slave licensing instances, please see license_usage.log on license master

Can we make this logging available locally without adding the remote license master as a search peer?

Thanks

bmacias84
Champion

with Splunk 6.2 you have the distributed management console which can be setup on a remote host as management server. It really replaces SOS and Splunk Deployment Monitor for most cases. The Licensing stats are gathered via rest api using the rest command | rest splunk_server=youSplunkLicenseMaster.local /services/licenser/pools. Read more @ http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/ConfiguretheMonitoringConsole. This view is only available to admins.

As a side note if you add your License Master as a search peer to your search heads the rest command which make up the Licensing page will work.

0 Karma

Ant1D
Motivator

Hi, this is a 6.1 instance. Are there any alternatives other than adding the License Master as a peer?

0 Karma

bmacias84
Champion

On the licensing master you could set up a summary index on for the saved searches which drive the license master UI. Then using event forwarding and routing send the summary to your indexers. This would require a transforms and props. Another alternative is to have a script which will poll the license master API with a limited read user and then you index the event on your indexers.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...