Installation

forwarder license expired

mmattek
Path Finder

our 4.1 forwarder license expired 2011-03-08 where to get a new one?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Some versions of 4.1 shipped with a forwarder license that expired too soon. You can get a forwarder licenseby downloading and unpacking the most recent 4.1 release.

Don't try to get it from 4.2, as it does not come with (or require) a separate forwarder license.

Jason
Motivator

This post contains a copy of the proper license so you don't have to download and unpack: http://splunk-base.splunk.com/answers/12167/

0 Karma

mmattek
Path Finder

negative.. the splunk-forwarder.license file is exactly the same as the one as splunk.license.. that has already been done.

0 Karma

MarioM
Motivator

and is your forwarder still forwarded data or did it stopped?

0 Karma

MarioM
Motivator

Verify the forwarder is not indexing AND forwarding.

From the GUI, you would follow these steps...

  1. click Manager > Forwarding and receiving > Forwarding defualts
  2. Select radio button "No" for "Store a local copy of forwarded events?"
  3. click Save button

This is equivalent to outputs.conf setting:

indexAndForward = false

0 Karma

MarioM
Motivator

if it doesnot index data it doesnot need license.

You just need to do the following:

a. Windows:

    # copy %SPLUNK_HOME%\etc\splunk-forwarder.license %SPLUNK_HOME%\etc\splunk.license

b.  Nix:

    # cp $SPLUNK_HOME/etc/splunk-forwarder.license $SPLUNK_HOME/etc/splunk.license
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...