Getting Data In

Can I enable distributed indexer using Enterprise Trial license ?

manojgeorge007
New Member

Hi - I am using Splunk Enterprise Trial license at home network for learning purpose.

I have installed Splunk(Linux) on my two machines within home network.
When I try to change the license configuration to Slave in one of the machine to make one as master and another as slave, it gives below error..

"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip="

As per documentation, distributed indexing is possible with Splunk Enterprise Trial license. Am I missing something?
Pls advise.

Thanks ,
Manoj

Tags (2)
0 Karma
1 Solution

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

View solution in original post

0 Karma

deejaybags
Engager

You could also request a splunk dev license. It will allow you to do the funky stuff like index clustering and search head clustering, and allows you to index 10G/day. It is great for home/lab set-ups like you describe you have.

0 Karma

raghu0463
Explorer

How to request a dev license please.

0 Karma

MuS
Legend

Hi raghu0363,

start here http://dev.splunk.com/page/developer_license_sign_up

cheers, MuS

0 Karma

neelamssantosh
Contributor

Hi Manoj,

Unfortunately, No is the answer.

Respective features are not available in Trail/Free.
Hope, Below link can help you better.
http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

All the best and Keep splunking.

0 Karma

Raghav2384
Motivator

Hey Manoj, are you trying to add One Ent Splunk Trial linux instance as a trial to second Ent Splunk Trial instance? If yes, it's not going to work as they are trial instances any way. Can point to a Master which has a purchased license key only.

Are you trying to use one instance as search heads and the second as indexer? If yes, distributed search is what you're looking for.

Pick an instance to be search head, click on Settings>>Distributed Search >> Search Peers>>Add New

Enter the Second instance's ip address followed by Management port. Something like 192.1.2.3:8089 and save.

Now you should have a dedicated search head and a dedicated indexer. Hope this help!

Thanks,
Raghav

0 Karma

manojgeorge007
New Member

Thank You Raghav , Neelam. Your response helps.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...