Installation

Can I create an instance on my local machine and monitor in production server using free or licensed version?

karthikannan
New Member
Error - Bad request- In handler 'localslave'. editTracker failed, reason='WARN': path=/masterlm/usage: This license does not support being a remote master. 

Actually what I'm looking is as of now I done the Splunk trial version setup in our application production server which is running remotely. So whenever I need to access Splunk Web, I’m connecting to the production server remotely.

Now I want to know, can I create the Splunk instance in my local machine and similarly that for my team members by referring the production server Splunk instance as the master? So that we can do search & reporting in Splunk without logging in production server? But ultimately the monitoring should be happening in our production server.

If yes, then can this be done in the free version or licensed version?

Thanks,
Karthik

Labels (1)
0 Karma
1 Solution

MuS
Legend

Hi karthikannan,

what you're looking for or trying to do, is called distributed search http://docs.splunk.com/Documentation/Splunk/6.3.0/DistSearch/Whatisdistributedsearch and cannot be done with the free license as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.3.0/Admin/MoreaboutSplunkFree first point under

What is included with Splunk Free?

 Distributed search configurations (including search head clustering) are not available.

You need to have a valid enterprise license to do so.

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi karthikannan,

what you're looking for or trying to do, is called distributed search http://docs.splunk.com/Documentation/Splunk/6.3.0/DistSearch/Whatisdistributedsearch and cannot be done with the free license as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.3.0/Admin/MoreaboutSplunkFree first point under

What is included with Splunk Free?

 Distributed search configurations (including search head clustering) are not available.

You need to have a valid enterprise license to do so.

Hope this helps ...

cheers, MuS

karthikannan
New Member

Thanks very much for the clarification!!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...