Security

How to change back license group from enterprise license to forwarder license?

mysicksi
Path Finder

Hi everyone,

I'm a total Splunk noob. The title basically says it all. I recently changed the group from enterprise to forwarder. Now I cannot access the GUI. Is there a way I can change it back from the CLI? Also, will this change affect the current operations of the heavy forwarder? Thank you.

0 Karma
1 Solution

ivanreis
Builder

Hi mysicksi,
please check if there is a stanza named as:
[license]
active_group = Forwarder

at $Splunk_Home/etc/system/local under server.conf

edit the server.conf , go to license stanza and change to:
[license]
master_uri = https://yourlicenseservername:8089

  • An example of : ://:

it can be either FQDN or Ipaddress of the server

active_group = Enterprise

save the changes and start splunk service running /opt/splunk/bin/splunk restart

For further information on server.conf check this document-> https://docs.splunk.com/Documentation/Splunk/8.0.0/Admin/Serverconf#License_manager_settings_for_con...

View solution in original post

0 Karma

Ishanjain
Engager

Is there a limitation on number of installation of Universal forwarder in Hosting environment (Server) assuming i have relevant license available?

0 Karma

ivanreis
Builder

Hi mysicksi,
please check if there is a stanza named as:
[license]
active_group = Forwarder

at $Splunk_Home/etc/system/local under server.conf

edit the server.conf , go to license stanza and change to:
[license]
master_uri = https://yourlicenseservername:8089

  • An example of : ://:

it can be either FQDN or Ipaddress of the server

active_group = Enterprise

save the changes and start splunk service running /opt/splunk/bin/splunk restart

For further information on server.conf check this document-> https://docs.splunk.com/Documentation/Splunk/8.0.0/Admin/Serverconf#License_manager_settings_for_con...

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...