Installation

What happens if a license slave cannot connect to the license master?

tpedone
Explorer

We want to start using the License Master feature in Splunk 4.2. What happens if the license slave loses connectivity to it's Master for a period of time? Are we adding one more potential point of failure?

Labels (1)
Tags (1)

Vishal_Patel
Splunk Employee
Splunk Employee

The slave is given a grace period for connectivity (I believe it is 24 hours). If the slave cannot connect in that time, it will disable search on its node until the problem is fixed, but keep indexing data.

tpedone
Explorer

I did some more searching and according to this page:
http://www.splunk.com/base/Documentation/latest/Admin/Aboutlicenseviolations

If a slave is orphaned, it generates a warning which counts against your 5 allowed violations in a given 30 day period. So it seems that search won't be disabled immediately. What's not clear is if that warning clears when the slave re-connects (in other words, does the warning count get reset when the slave re-connects

joshualemoine
Path Finder

Is this still true with a "no fault" license? I would think it may be, since the license, including the part about being a no fault license, lies on the License Master, so if the IDX node couldn't communicate with it, it would still eventually give up the ghost and prevent you from searching.

For whatever reason, or SD/LM has connectivity issues from time to time, and it will show up in the splunkd.log file. It never lasts more than a few hours, and we do get messages in the web console about it, but up till now it hasn't stopped our searches.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...