Installation

If I move license masters, will I lose historical license data?

vanderaj2
Path Finder

Hello,

I'm considering moving my license master from one server to another. If I do that, will I lose past historical data on license usage (i.e. prior 30 days metrics on license usage)?

Thanks!

Labels (1)
0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

As long as you have a distributed environment, e.g., Clustered with proper replication, your logging metrics are all stored in the _internal index. This also assumes that you have a long retention set on this index...

In that case, you can search against it from any search peer that is connected to the indexing cluster / tier..

View solution in original post

vanderaj2
Path Finder

Perfect! Thanks All.....I appreciate you guys weighing in on this. Indeed, we are pushing all the _internal logs down to the indexing cluster (which all of the elements in our distributed environment can search).

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

As long as you have a distributed environment, e.g., Clustered with proper replication, your logging metrics are all stored in the _internal index. This also assumes that you have a long retention set on this index...

In that case, you can search against it from any search peer that is connected to the indexing cluster / tier..

gjanders
SplunkTrust
SplunkTrust

Assuming you are forwarding your license master data to the indexing tier, there will be no loss of licensing information as all the data will exist in the indexer(s)

You can run searches to show licensing information on any search head FYI, you just need to know to use the correct search syntax.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...