Installation

Licence violation - don't understand why ?

drouillot
New Member

Hi all,

I installer a splunk few weeks ago, played 3 days on one server with 3 forwardings (oneself and 2 on others servers).

I reconnect today and transform my licence (was entreprise trail) into a free licence because I have 2 warning messages :

1- Missing or malformed messages.conf stanza for LM_LICENSE:SLAVE_WARNING_COUNT_SELF 05/05/2019 à 12:18:01 
2- Missing or malformed messages.conf stanza for LM_LICENSE:SLAVE_WARNING__1557007200_ 05/05/2019 à 12:18:01

However, when I watch the licence usage reporting, I have 3 hard warning et I read I'm in violation.

For the last 30 days, my daily licence quota was about 40%. (Licence-->Licence usage reporting).

index=_internal per_index_thruput earliest=-60d@d latest=now | timechart span=1d eval(sum(kb)/1024) as "Daily Indexing Volume in MB"

--> give the same result : I stay below 500 M

Is there somebody to help me understand what's wrong with my config ?

Thanks

0 Karma

woodcock
Esteemed Legend

You might think that only Indexers need a license but that is not so. When you FTR (first-time-run) Splunk, it starts a 30-day timer on the Free Enterprise License no matter what role your Splunk server has. At then end of that 30 days you either need to reinstall or have it pointed to a license master with valid license. Yes, this means all of your Search Heads, Heavy Forwarders, Deployers, Cluster Masters, and Monitoring Consoles.

0 Karma

teunlaan
Contributor

What is "a few weeks ago" ?? the Trail license is for only 60 day's

0 Karma

drouillot
New Member

Installed on 3rd april

I paste the result of : index=_internal per_index_thruput earliest=-60d@d latest=now | timechart span=1d eval(sum(kb)/1024) as "Daily Indexing Volume in MB"

2019-04-03 80.9005317687988
2019-04-04 425.2479381561279
2019-04-05 425.5762710571289
2019-04-06 426.0857295989990
2019-04-07 425.6220388412476
2019-04-08 425.4880132675171
2019-04-09 425.1983909606934
2019-04-10 425.6022958755493
2019-04-11 428.0690059661865
2019-04-12 429.9727134704590
2019-04-13 428.4483451843262
2019-04-14 425.8094844818115
2019-04-15 425.7821359634399
2019-04-16 426.0781307220459
2019-04-17 427.8077001571655
2019-04-18 426.2353906631470
2019-04-19 427.5133113861084
2019-04-20 429.3108539581299
2019-04-21 427.2381610870361
2019-04-22 425.1466999053955
2019-04-23 425.4117126464844
2019-04-24 425.9489107131958
2019-04-25 434.7730140686035
2019-04-26 425.7145261764526
2019-04-27 425.1333408355713
2019-04-28 425.3632974624634
2019-04-29 426.0917139053345
2019-04-30 426.2192420959473
2019-05-01 429.6561326980591
2019-05-02 432.3099679946899
2019-05-03 425.6254653930664
2019-05-04 425.3939561843872
2019-05-05 281.9827365875244
2019-05-06 94.9014148712158

I'd like to find why I have 3 critical violation error.
Any suggestions ? or diagnostics to help me to understand ?
Thanks in advance

0 Karma

Sukisen1981
Champion

have you checked previous 30 days usage reports in the licensing console?

0 Karma

DavidHourani
Super Champion

any updates ? Is this the first time you install Splunk on this server ? Could be because you've already used it before... Try updating or reinstalling..

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...