Getting Data In

1MB Forwarder license expiring?

Jason
Motivator

At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where this came from - was this a bug?

user@host $ bin/splunk show license
Current Daily Usage Amount:     0
Expiration date:                2011-03-08T01:07:37-0500
Expiration State:               7
License level:                  1 MB
Product:                        Enterprise
License violations:
Max Violations:
Peak usage:                     0 MB
Days remaining:                 6 day(s)
Violation Period:
Tags (2)
1 Solution

Ellen
Splunk Employee
Splunk Employee

Ellen
Splunk Employee
Splunk Employee

This is a known issue. More details and options can be found here:
http://answers.splunk.com/questions/12167/why-is-the-license-on-the-forwarder-search-head-displaying...

Jason
Motivator

Thanks - This link actually has a copy of the correct license for folks out there. Good to know it's a known bug.

0 Karma

yannK
Splunk Employee
Splunk Employee

A simple solution is to download a splunk 4.1.7 zip/tar.gz and use the forwarder license shipped in it /etc/splunk-forwarder.license

But at this step, why not upgrade directly to 4.1.7

Jason
Motivator

Upgrading will not change the license by default.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This was a bug in one of the releases. You should be able to replace it with the forwarder license from a current release of Splunk. Note that this is mostly of no consequence on a forwarder, since the results of a license lockout are that you can't search, and there is (or should be) nothing to search on a forwarder.

0 Karma

Jason
Motivator

But for other non-indexing uses, such as on a search head, it is of vital importance.

0 Karma

David
Splunk Employee
Splunk Employee

There was a Splunk Answers a bit ago that said they accidentally shipped a bad forwarder.license in one release. It was a bit scant on details, so it's hard to confirm that it is your issue, but it certainly sounds like it.

http://answers.splunk.com/questions/11192/splunk-forwarder-license

Jason
Motivator

More details (and proper license) in #12167.

0 Karma

Jason
Motivator

The expiring license file starts with forwarder@splunk.com and the encrypted text began with RV7. When the license was changed to splunk-forwarder.license from the 4.1.6 64-bit linux tgz package, the date went back to 2020-06-08 as expected (that file starts with forwarder@splunk.com and the encrypted text starts with JbX).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...