Installation

How to resolve overreporting of license usage after temporary storage issue?

devinmclean
Path Finder

Our license server ran into a space issue where we ran under 1,000 MB of space available. Therefore, it stopped indexing. This went unnoticed for a few days, and it fixed itself for a day or two, and then went back under 1,000 MB again. This causes the license measurements to go completely off the charts. For example, our indexers are only consuming about 500 GB all together right now, but the license server things we're at 4.5TB. Is there a way to correct the license server's values?

Labels (1)
0 Karma

rafamss
Contributor

Hi @devinmclean,

What is the size of your license? Usually when this happen you will need request a support for your Splunk team to fix your license.
Other thing to do is analysis how is the offender of this sudden increase and in some cases, disable the collect of data for a while for to do this.

I hope help you.

[ ]s
Rafael Martins

0 Karma

devinmclean
Path Finder

Hey @rafamss,

The license is not actually being exceeded. The license server is displaying incorrect information due to it shutting down and not indexing data (caused by the HD on the server being full). I'm wondering if anyone else has seen this kind of behavior and how to fix it.

0 Karma

rafamss
Contributor

Sure @devinmclean,

I've never passed for any similar event like your, but try this tips, I hope this help you.

By the way, did you look the log of license master? $SPLUNK_HOME/var/log/splunk/license_usage.log to find any anomalous event?

A workarround would be delete the licenses of your environment and put this again.

There is some know issues and workarrounds of Splunk 7.0 release notes, see this: http://docs.splunk.com/Documentation/Splunk/7.0.0/ReleaseNotes/Knownissues

[ ]s
Rafael Martins

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...