Splunk Search

Error in "litsearch" command

JoshuaJJ
Path Finder

Good morning, 

Getting a weird error this morning when trying to run searches. It is saying that m license is expired, or I have exceeded your license limits too many times. 

 

1. I have a valid Enterprise License at about 750GB a day

2. Within the license manager all is well. No violations, valid license, etc. 

3. Peers are associated to the license group (750GB is what I allocated for it) 

4. Everything looks green with no messages 

 

Not sure what is causing this issue but sometimes search will work and sometimes it wont. However, it  will always throw the litsearch error. 

0 Karma
1 Solution

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JoshuaJJ ,

check if yu have network issues in communication between Indexers and License Master.

Otherwise, open a case to Splunk Support.

Remember to download and send them a diag from the machine that's sending the message and from an indexer.

Ciao.

Giuseppe

JoshuaJJ
Path Finder

I believe I figured out what was wrong.  Turns out our admin forgot to point the newly installed SH cluster member to the license manager.  It is now pointing to the LM. How long does it take for the lit search error to clear? 

0 Karma

dural_yyz
Motivator

Ideally it should clear right away, however if not try manually electing a new SH captain and wait 5-10 minutes for the SH bundle to replicate.

JoshuaJJ
Path Finder

Error is gone! Thank you all for your help 🙂 

0 Karma

JoshuaJJ
Path Finder

Awesome, will do this right away! 

 

Thanks, 

 

JJ 

0 Karma

JoshuaJJ
Path Finder

Will do. Thanks for your speedy response! 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...