Installation

distributed search issue - duplicate licenses

castle1126
Communicator

Hi all,

My old, primary Splunk indexer/search head is being retired (v4.1.4). In its place is 4 new indexing servers that are carrying the indexing load for me (all running v4.1.5). Each of these 4 systems were built from scratch, with indexes.conf being moved to them.

I'm trying to set this old server to be a search head for the new systems, allowing it to run some scheduled searches this weekend before we retire the server. When I add the search peers to the old system via the GUI, they all go in nicely without complaint. When I log back into the old server's GUI again I get this message on the top of my browser:

Unable to distribute to peer named xxx at uri https://xxxx:8089 because peer has status = "Duplicate License".

When I look at Manager->Distributed search-> Search Peers I see the 4 peers showing a status of "duplicate license".

I've dug around through logs on all systems and nothing pops out as being in error, etc.

Any ideas?

1 Solution

ftk
Motivator

Sounds like you still have your old license installed on your old indexer/new search head, and you used the same license at one (or all?) of the new indexers.

At the search head you want to change the license to the Forwarder license (as long as it doesn't do any indexing) and your troubles will go away.

View solution in original post

ftk
Motivator

Sounds like you still have your old license installed on your old indexer/new search head, and you used the same license at one (or all?) of the new indexers.

At the search head you want to change the license to the Forwarder license (as long as it doesn't do any indexing) and your troubles will go away.

castle1126
Communicator

That was it! I thought I had changed licenses prior to setting up distributed searches but didn't. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...