Deployment Architecture

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times.

richkappler
Path Finder

Probably the wrong board, choices were limited.
In our dev environment we have a 3 node sh cluster, a 3 node idx cluster, an ES sh and a few other anciliary machines (DS, deployer, UF's HF's, LM, CM, etc). All instances use the one LM. 

On the SHC we are unable to search, getting the subject line message, yet on the ES SH we can search fine and no error message. The nodes of the SHC are "phoning home" to the LM. Licensing settings (indexer name, manager server uri) have been verified as correct. All nodes show having connected to the LM within the last minute-ish.

Not sure where to look from here.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

there should be more information on _internal log. Just query from it like

index=_internal LM* OR expired

That should show you more information about y our issue.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...