Splunk Dev

How License Master will identify the components of Splunk?

ganesh999
Engager

Hi Splunkers,

I would like to know how the license master will identify the components of Splunk. which is DS, HF, UF, CM, Deployer, SH and Indexer.

Thanks in Advance,
Ganesh

Tags (1)
0 Karma

bpadmanbhachari
Splunk Employee
Splunk Employee

The license slaves are connected to the license master via management port. License master every minute will hit the license slaves rest point at 8089 port which discloses information about license slave. If you see today's usage to open in search you will be able to find the rest command and what information is collected from slave. Also, you can try hitting the rest API directly to know what information is disclosed from slave to master.

0 Karma

nickhills
Ultra Champion

Just nitpicking, but I don't think the License Master 'hits' the Slaves, at least from a TCP perspective.
Slaves open a socket to the webservice on the Master and send metrics to it. Its a minor point, but relevant if someone is having to configure firewall ports etc.

If my comment helps, please give it a thumbs up!

bpadmanbhachari
Splunk Employee
Splunk Employee

But in today's license usage when i opened in search it is using rest command hitting the rest point of the slaves. So i opened same rest API via 8089 port and found the same information. Based on the SPL i just understood this way.

0 Karma

rmjharris
Path Finder

The only thing the license server is concerned with is the amount of data being indexed. It monitors the amount of data that is indexed by other instances that are configured to use it as a license server. The instance type is unimportant.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...