Getting Data In

We have "indexAndForward = false" configured, but why are heavy forwarders listed in results from license_usage.log and metrics.log?

kearaspoor
SplunkTrust
SplunkTrust

Working on better alerting on indexing volume/license usage and the like and I've stumbled across something in-explicable. We have 4 Heavy Forwarders that all have default/outputs.conf with [tcpout] indexAndForward = false

Now when I look at:

index=_internal host=<nameing convention of Splunk infrastructure devices) source="*metrics.log" group="per_index_thruput" series=main| timechart span=30m per_second(kb) BY host

One of the heavy forwarders shows up in the list of hosts (along with the indexers I'd expect)

Even more confusing is when I look at:

index=_internal source=*license_usage.log type="RolloverSummary"

This returns the vast majority of events from our license master with "pool" listed as the "auto_generated_pool_enterprise" as I'd expect. But it also shows all 4 of our heavy forwarders with "pool" listed as "auto_generated_pool_download-trial" or "auto_generated_pool_forwarder"

Looking at the Distributed Management Console app, under License Usage... if I look at all pools split by pool, I see all 3 of these pools (download-trial, enterprise and forwarder). When I look at it split by indexer, the list of indexers is in GUID so it's hard to correlate back to device, but there's 10 + "Other" listed... and we only have 5 indexers in our environment... so there's at least 5 more than expected.

I'd like to get this cleaned up so we can be certain that we're accurately reporting on which devices are consuming license and at what rate.

Anyone know why one HF would be found under

index=_internal  source="*metrics.log" group="per_index_thruput" series=main

and all of them would be found under:

index=_internal source=*license_usage.log type="RolloverSummary"

As stated above... index and forward is false for all of them.

Thank you!

0 Karma

hemendralodhi
Contributor

Can you convert all your HF to have forwarder only license? HF doesn't need to connected to license server unless it is indexing. Restart the server after change.
$ splunk list licenser-groups
$ splunk edit licenser-groups Forwarder -is_active 1
$ splunk restart
$ splunk list licenser-groups

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...