Installation

Why does Splunk enterprise license show: Status= FROM_THE_FUTURE?

Bill_B
Communicator

I am running Splunk 6.0.4 on linux. On the "Licensing" page, my enterprise license shows a status of "FROM_THE_FUTURE" instead of "valid" like in the documentation. Why is this and what does it mean?
Also, the volume of my license is 5,120 MB but Effective daily volume is 0 MB. Why?

Any help is greatly appreciated.

Labels (2)
0 Karma
1 Solution

jgreenleaf
Explorer

Licenses are only valid after they are issued, not before. This is to prevent you from buying a license and then sending it x time_units in the past, as that way splunk would miss out on x time_units of license fees.

To resolve this issue just run "ntpdate pool.ntp.org".

View solution in original post

edeefelt
New Member

I seem to be showing three identical licenses (all the same size) which I'm guessing means they really all are the same license:
one expired
one good for another year (shows valid)
one good for two more years but shows FROM_THE_FUTURE
Is there a way to tell from the "All license details" page if these are all the same license?
I'm guessing this means an expired license was updated for a year, then for a second year but it doesn't go in to effect until the current one finishes (as pointed out by @David.nelson-gal)

0 Karma

david_nelson-ga
New Member

I'm having the same problem but what is frustrating is two things:

1) This is a renewal license, not a beginning license. All my historic data has been collected under existing licenses.
2) Today is the day my 2014 license expires. It seems absurd to make me wait until midnight to add it.
3) How do I know its going to work? That is, how do I know the difference between "Don't worry, it will work in the morning" and a botched license file generation which means I'm flying blind for a few days while I hassle with Splunk to fix?

If everything works, it seems like unneeded stress for renewing customers. If it breaks, I am really not going to be happy and will start considering alternatives.

0 Karma

jgreenleaf
Explorer

Licenses are only valid after they are issued, not before. This is to prevent you from buying a license and then sending it x time_units in the past, as that way splunk would miss out on x time_units of license fees.

To resolve this issue just run "ntpdate pool.ntp.org".

bpenn_splunk
Splunk Employee
Splunk Employee

As an addition to this thread, one of my customers pointed out that they applied their renewal license and  received the same "FROM_THE_FUTURE" status. The cause of this is that the "create date" field, which is in epoch form and the actual start date of the renewal, is in the future. This should clear once the create/start date arrives, but it may require a restart of Splunk.

Tags (2)
0 Karma

Bill_B
Communicator

Thank you. This solves an entire licensing issue I have been working on. Turns out my servers thought it was 2013.

0 Karma

dshpritz
SplunkTrust
SplunkTrust

alt text

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...