Splunk Search

Error in "litsearch" command

JoshuaJJ
Path Finder

Good morning, 

Getting a weird error this morning when trying to run searches. It is saying that m license is expired, or I have exceeded your license limits too many times. 

 

1. I have a valid Enterprise License at about 750GB a day

2. Within the license manager all is well. No violations, valid license, etc. 

3. Peers are associated to the license group (750GB is what I allocated for it) 

4. Everything looks green with no messages 

 

Not sure what is causing this issue but sometimes search will work and sometimes it wont. However, it  will always throw the litsearch error. 

0 Karma
1 Solution

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JoshuaJJ ,

check if yu have network issues in communication between Indexers and License Master.

Otherwise, open a case to Splunk Support.

Remember to download and send them a diag from the machine that's sending the message and from an indexer.

Ciao.

Giuseppe

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

0 Karma

dural_yyz
Motivator

Ideally it should clear right away, however if not try manually electing a new SH captain and wait 5-10 minutes for the SH bundle to replicate.

JoshuaJJ
Path Finder

Error is gone! Thank you all for your help 🙂 

0 Karma

JoshuaJJ
Path Finder

Awesome, will do this right away! 

 

Thanks, 

 

JJ 

0 Karma

JoshuaJJ
Path Finder

Will do. Thanks for your speedy response! 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...