Splunk® Enterprise

Admin Manual

Download manual as PDF

Download topic as PDF

Allocate license volume

You can aggregate compatible Splunk Enterprise licenses into stacks of available license volume. You can then allocate license volume from the stack to one or more license pools. Indexers can then be assigned to a pool in order to draw licensing volume from the pool.

Besides indexers, other Splunk Enterprise instances must be assigned to a Splunk Enterprise license pool, so that they can access certain Splunk Enterprise features, such as distributed search. As a general rule, assign all of your Splunk Enterprise instances, with the exception of forwarders, to a license pool. See Licenses and distributed deployments.

Note: Stacks and pools are not available with the Free or Enterprise Trial licenses.

License terms diagram

Stacks

Certain types of Splunk licenses can be aggregated together, or stacked so that the available license volume is the sum of the volumes of the individual licenses. This allows you to increase indexing volume capacity over time without needing to swap out licenses. Instead, you simply purchase additional capacity and add it to the appropriate stack.

Enterprise licenses, including "no-enforcement" licenses, and Sales Trial licenses can be stacked together and with each other.

Stacks are unavailable with these license types:

  • Enterprise Trial
  • Free
  • Dev/Test. If you install a Dev/Test license over an Enterprise license, the Enterprise license will be deleted.
  • Forwarder

Groups

A license group contains zero or more stacks. A stack can be a member of only one group.

Only one group can be active at a time. This means that a given license master can only administer pools of licenses of one group at a time.

The groups are:

  • Enterprise/Sales Trial group -- This group allows stacking of purchased Enterprise licenses, along with Sales Trial licenses.
  • Enterprise Trial group -- This is the default group when you first install a new Splunk platform instance. You cannot stack Enterprise trial licenses. If you switch an instance to a different group, you will not be able to switch back to the Enterprise trial group.
  • Free group -- This group accommodates Splunk Free installations. When an Enterprise Trial license expires after 60 days, that Splunk instance is converted to the Free group. You cannot stack Splunk Free licenses.
  • Forwarder group -- This group is for forwarders that function solely as forwarders and do not perform other roles, such as indexing. You cannot stack Forwarder licenses.

Subgroups

There are several types of subgroups, including DevTest and Production. A license can belong to only a single subgroup.

Subgroups were introduced in Splunk Enterprise 6.5. A license with no subgroup, such as a license issued before 6.5, is treated as though its subgroup is Production.

Pools

A license pool consists of licensing volume allocated from a stack. A stack can contain multiple pools, each with a portion of the stack's total licensing volume.

The license master manages the pools. Each of the master's license slaves can access only a single pool.

You can manage volume usage by creating multiple pools and assigning indexers to specific pools. For example, you can assign your production and test indexers to separate pools. That way, you can ensure that testing activity does not impinge on production needs.

License master

A license master is a Splunk Enterprise instance that controls one or more license slaves. From the license master, you can define pools, add licensing capacity, and manage license slaves.

License slaves

A license slave is a Splunk Enterprise instance controlled by a license master. The license master grants each slave access to a license pool.

PREVIOUS
Licenses and distributed deployments
  NEXT
Install a license

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.1.0, 7.1.1, 7.1.2


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters