Getting Data In

what license for my 4.2 forwarder ?

mataharry
Communicator

I installed 4.2 splunk, and made it a forwarder (not lightweight or universal forwarder) Because I want to do some filtering on it before sending to the indexer.

But I got license errors. I looked for the $SPLUNK_HOME/splunk-forwarder.license as I used to do on 4.1. But i only found a trial license !!!

where is my forwarder license ?

Tags (2)
1 Solution

yannK
Splunk Employee
Splunk Employee

On 4.2 the easiest method to change the license group to the forwarder license group. There is no splunk-forwarder.license file in $SPLUNK_HOME/etc/ anymore.

see here http://www.splunk.com/base/Documentation/latest/Admin/TypesofSplunklicenses#Forwarder_license

Using the UI : You have to go to the web UI, manager > Licensing > change license group to forwarder license. Do that for your forwarders and dedicated deployment servers.

important remarks :

  1. there is not yet a method to do it from the CLI on 4.2.0, it will be possible in 4.2.1.
  2. you cannot do that anymore for the 4.2 search-heads, you need to add them as slave of your indexer license pool.


Another more complex method is to create a license pool for the forwarders or search-heads.

  1. on the manager on the indexer/license server
  2. create a license pool with 1MB/day (taken from the real license)
  3. to simplify make this pool the default for new slave servers (your forwarders)
  4. on the forwarder, go to the manager>license and make it a slave of the indexer/license server (default is yourindexerip:8089 )

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi guys

just as addition to this topic:
I tried to setup a heavy forwarder by script and encountered the problem to change/activate the license by script. after a small chat with yannK I found this solution, just add the following to your servers.conf and your done:

[license]

active_group = Forwarder

kudos go to yannK 😉

chicodeme
Communicator

worked for me on 4.2.2 ... added to splunklightforwarder app that is deployed out..

0 Karma

yannK
Splunk Employee
Splunk Employee

On 4.2 the easiest method to change the license group to the forwarder license group. There is no splunk-forwarder.license file in $SPLUNK_HOME/etc/ anymore.

see here http://www.splunk.com/base/Documentation/latest/Admin/TypesofSplunklicenses#Forwarder_license

Using the UI : You have to go to the web UI, manager > Licensing > change license group to forwarder license. Do that for your forwarders and dedicated deployment servers.

important remarks :

  1. there is not yet a method to do it from the CLI on 4.2.0, it will be possible in 4.2.1.
  2. you cannot do that anymore for the 4.2 search-heads, you need to add them as slave of your indexer license pool.


Another more complex method is to create a license pool for the forwarders or search-heads.

  1. on the manager on the indexer/license server
  2. create a license pool with 1MB/day (taken from the real license)
  3. to simplify make this pool the default for new slave servers (your forwarders)
  4. on the forwarder, go to the manager>license and make it a slave of the indexer/license server (default is yourindexerip:8089 )

chicodeme
Communicator

4.2.3 is out.. what is cmdline option?

jbsplunk
Splunk Employee
Splunk Employee

Is any indexing taking place on the full forwarder? If so, you'll need to have access to an enterprise license stack.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi Guys

since 4.2.1 is out now, what would be the CLI command to change the license? And what if your not using a license master at all?

0 Karma

yannK
Splunk Employee
Splunk Employee

Even if there is no indexing on the full forwarder, you will have to add it to a license pool (no more splunk-forwarder.license included in the new installer)

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...