We started getting license warnings on the license master and after updating the license to 15G I can confirm the ui shows 15gb, however gives a warning for the indexer connecting to it has run out of license. On the indexer when I list all the licenser messages I see:
d459b5b73aa7e48c37412f233c8f2237
category:license_window
create_time:1433203200
description:This pool has exceeded its configured poolsize=15 bytes. A warning has been recorded for all members
pool_id:auto_generated_pool_enterprise
severity:WARN
slave_id:D746D644-6CC5-4F2D-B6FF-A71EDB69607A
stack_id:enterprise
Somehow the indexer seems to think it is a 15byte license.
On the license master I see:
Licenses Volume Expiration Status
Splunk Enterprise 15,360 MB xxxxx valid Delete
Effective daily volume 15,360 MB
Pools Indexers Volume used today
auto_generated_pool_enterprise 835 MB / 15,360 MB Edit | Delete
<hostname> 835 MB (5.436%)
Add pool
After adding the license I ended up restarting license master as well as indexer with the hope that maybe the license was not being recognized. Now when I try to search an index I do not see any data at all. Do you think this could be because of the license warnings? Or does bouncing splunk cause data to be lost?
... View more