Deployment Architecture

Is it possible to use the Splunk Cloud license master for on-prem Heavy Forwarders?

konstr
Path Finder

I'm deploying an on-prem architecture consisting of a deployment server and a number of Heavy Forwarders forwarding data into Splunk Cloud. The on-prem components are only forwarding and not indexing.

I was wondering if it is possible to have all of the on-prem Splunk instances (DS and HFs) act as license slaves to the splunk cloud license master. And how to do that? I tried pointing them to the Splunk cloud license master but the connection times out. There isn't clear documentation on if this is possible.

I am aware that since the HFs aren't indexing I could use a forwarder license and for the DS request a 0MB license from splunk. However, connecting them to the Splunk Cloud license master seems more future proof, and allows for expansion and possible changes in the future, including "forward and indexing".

1 Solution

amiracle
Splunk Employee
Splunk Employee

We do not offer the ability to connect to the splunk cloud license master. The two options you have are 1) get the 1mb license from support to install in your on-Prem splunk servers (HF’s, SH’s, DS, etc.) 2) get the dev license if you want to test sources in your own splunk deployment (dev.splunk.com).

View solution in original post

amiracle
Splunk Employee
Splunk Employee

We do not offer the ability to connect to the splunk cloud license master. The two options you have are 1) get the 1mb license from support to install in your on-Prem splunk servers (HF’s, SH’s, DS, etc.) 2) get the dev license if you want to test sources in your own splunk deployment (dev.splunk.com).

abk_hex
Loves-to-Learn Lots

@amiracle  I have a question out of this, do i have to use the 0Mb license separately on all the server like HF and DS. Or I can make DS as license master and point HF towards it. 

as I did make DS as license master and point HF towards it., but still not seeing logs from HF to cloud

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...