Installation

License server work principles

guahos
Explorer

Hello!
I am planning the following setup:
3 single-site indexing clusters in 3 separate locations and Deployment/License server and the Search Head at one of 3 sites.
And I have a couple of questions regarding License server work principles:
- How does it actually count the amount of stored logs? Does indexing peers send the information about how much data they have stored to the License server? Or does Cluster master send that info? Or forwarders send the info about how much data have they forwarded to indexers?
- What will happen if the License server goes down? Will data still be storing into indexers while License server is down? Would searching be available while License server is down?

Labels (3)
0 Karma
1 Solution

gfuente
Motivator

Hello

The indexers are the nodes that report how much they are indexing. If an indexer can`t connect to the License Server in 24 hours, it will generate a warning (the same as if you index more than your total license volume)

The indexers will never stop indexing data due to license issues.

Regards

View solution in original post

0 Karma

nkourtidis_splu
Splunk Employee
Splunk Employee

The right answer is 72 hours and can be found here:

http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Aboutlicenseviolations#About_the_connection_...

the license slaves communicate their usage to the license master every minute. If the license master is down or unreachable for any reason, the license slave starts a 72 hour timer. If the license slave cannot reach the license master for 72 hours, search is blocked on the license slave (although indexing continues)

gfuente
Motivator

Hello

The indexers are the nodes that report how much they are indexing. If an indexer can`t connect to the License Server in 24 hours, it will generate a warning (the same as if you index more than your total license volume)

The indexers will never stop indexing data due to license issues.

Regards

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...