Splunk Search

Error in "litsearch" command

JoshuaJJ
Path Finder

Good morning, 

Getting a weird error this morning when trying to run searches. It is saying that m license is expired, or I have exceeded your license limits too many times. 

 

1. I have a valid Enterprise License at about 750GB a day

2. Within the license manager all is well. No violations, valid license, etc. 

3. Peers are associated to the license group (750GB is what I allocated for it) 

4. Everything looks green with no messages 

 

Not sure what is causing this issue but sometimes search will work and sometimes it wont. However, it  will always throw the litsearch error. 

0 Karma
1 Solution

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JoshuaJJ ,

check if yu have network issues in communication between Indexers and License Master.

Otherwise, open a case to Splunk Support.

Remember to download and send them a diag from the machine that's sending the message and from an indexer.

Ciao.

Giuseppe

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

0 Karma

dural_yyz
Motivator

Ideally it should clear right away, however if not try manually electing a new SH captain and wait 5-10 minutes for the SH bundle to replicate.

JoshuaJJ
Path Finder

Error is gone! Thank you all for your help 🙂 

0 Karma

JoshuaJJ
Path Finder

Awesome, will do this right away! 

 

Thanks, 

 

JJ 

0 Karma

JoshuaJJ
Path Finder

Will do. Thanks for your speedy response! 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...