Splunk Enterprise Security

splunkd.log has license_warnings_update_interval messages every 20 seconds

diptij
Path Finder

I had converted my Splunk Head to use SSL.

I added /opt/splunk/etc/system/local/web.conf and updated [settings] to put the enableSplunkWebSSL, privKeyPath, serverCert.

It seemed to work.

However, the /opt/splunk/var/log/splunk/splunkd.log file keeps showing the following warnings every 20 seconds:

08-28-2020 23:41:09.135 +0000 INFO  LMStackMgr - license_warnings_update_interval=auto has reached the minimum threshold 10.  Will not reduce license_warnings_update_interval beyond this value.

So, I undid the web.conf changes and restarted splunk but I'm still seeing the license_warnings_log*.

Help please.

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Is this a standalone box or distributed environment with separate License Master? And is it a Splunk Enterprise, Trial or Free?

r. Ismo

0 Karma

diptij
Path Finder

A distributed environment with 1 splunk head and 1 splunk indexer.  The head is configured to be the License master.  

It is a Splunk Enterprise with a license.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...