Getting Data In

How to set up a license for a Heavy Forwarder that is also a Deployment Server?

andrewdidone
Path Finder

Hi.

I have an Indexer/SearchHead/Deploy server sitting on one zone, and a Heavy Forwarder/Deploy server sitting on another zone. Currently my license installed on the Indexer. Since the Heavy Forwarder is a Deployment Server, i am unable to use a free or forwarder license. How would i set up licensing here? Would i configure the forwarder as a slave and point it to the Indexer?

I've tried this and I receive the following error:

Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: This license does not support being a remote master. from ip='  

Does this mean i need a specific license that allows a slave connection?

Thanks,
Andrew

1 Solution

andrewdidone
Path Finder

Answering my own here. The answer is Yes. You set it up as a slave. My license was just an invalid one. After a proper license install, it seems to work fine now.

Hope this helps anyone else.

View solution in original post

nickstone
Path Finder

anyone know how this works with Splunk Cloud? or is it the same? Just point at Splunk Cloud as License Server?

0 Karma

andrewdidone
Path Finder

Answering my own here. The answer is Yes. You set it up as a slave. My license was just an invalid one. After a proper license install, it seems to work fine now.

Hope this helps anyone else.

napomokoetle
Communicator

Do you know if a pure Heavy Forwarder with NO deployment function and NO local indexing require a license? Or is it taken just like a Universal Forwarder?

0 Karma

lakshman239
Influencer
0 Karma

andrewdidone
Path Finder

If there is no deploy server functionality, and no indexing then i believe no license required. it'll just act as a relay. You just need to set up forwarding to the main indexer. Standard port is 9997.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...