Installation

License server work principles

guahos
Explorer

Hello!
I am planning the following setup:
3 single-site indexing clusters in 3 separate locations and Deployment/License server and the Search Head at one of 3 sites.
And I have a couple of questions regarding License server work principles:
- How does it actually count the amount of stored logs? Does indexing peers send the information about how much data they have stored to the License server? Or does Cluster master send that info? Or forwarders send the info about how much data have they forwarded to indexers?
- What will happen if the License server goes down? Will data still be storing into indexers while License server is down? Would searching be available while License server is down?

Labels (3)
0 Karma
1 Solution

gfuente
Motivator

Hello

The indexers are the nodes that report how much they are indexing. If an indexer can`t connect to the License Server in 24 hours, it will generate a warning (the same as if you index more than your total license volume)

The indexers will never stop indexing data due to license issues.

Regards

View solution in original post

0 Karma

nkourtidis_splu
Splunk Employee
Splunk Employee

The right answer is 72 hours and can be found here:

http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Aboutlicenseviolations#About_the_connection_...

the license slaves communicate their usage to the license master every minute. If the license master is down or unreachable for any reason, the license slave starts a 72 hour timer. If the license slave cannot reach the license master for 72 hours, search is blocked on the license slave (although indexing continues)

gfuente
Motivator

Hello

The indexers are the nodes that report how much they are indexing. If an indexer can`t connect to the License Server in 24 hours, it will generate a warning (the same as if you index more than your total license volume)

The indexers will never stop indexing data due to license issues.

Regards

0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...