<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk license warnings?? in Security</title>
    <link>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292997#M13483</link>
    <description>&lt;P&gt;The Splunk license goes by how much you index per day. What version of Splunk are you running?&lt;/P&gt;

&lt;P&gt;Before 6.5, Splunk will stop you from searching the data after 5 license violations in a 30 day period. So you would need to violate your license 5 separate days in a 30 day period for it to block you from searching&lt;/P&gt;

&lt;P&gt;If your on 6.5 or greater than Splunk will not block you from searching after 5 violations in a month, but I believe you will need to TrueUp your usage at the end of the year if you continuously go over your license. &lt;/P&gt;

&lt;P&gt;Indexing never stops, even if you violate the license &lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2017 20:23:14 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2017-03-23T20:23:14Z</dc:date>
    <item>
      <title>splunk license warnings??</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292996#M13482</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;i am bit confused with license warnings, if i have a license of 100gb and i reached my limit  with in half day (12hrs) so at that point i will get a license violation which will not stops me from indexing ans searching. so when will i get my second violation, do i get the next minute as i have not stopped my indexing ?? if not when will i get my second violation??&lt;/P&gt;

&lt;P&gt;can anyone help me in understanding this ??&lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:11:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292996#M13482</guid>
      <dc:creator>AzmathShaik</dc:creator>
      <dc:date>2017-03-23T20:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license warnings??</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292997#M13483</link>
      <description>&lt;P&gt;The Splunk license goes by how much you index per day. What version of Splunk are you running?&lt;/P&gt;

&lt;P&gt;Before 6.5, Splunk will stop you from searching the data after 5 license violations in a 30 day period. So you would need to violate your license 5 separate days in a 30 day period for it to block you from searching&lt;/P&gt;

&lt;P&gt;If your on 6.5 or greater than Splunk will not block you from searching after 5 violations in a month, but I believe you will need to TrueUp your usage at the end of the year if you continuously go over your license. &lt;/P&gt;

&lt;P&gt;Indexing never stops, even if you violate the license &lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292997#M13483</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-03-23T20:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license warnings??</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292998#M13484</link>
      <description>&lt;P&gt;Here's the basic doc for that.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Aboutlicenseviolations"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Aboutlicenseviolations&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Apparently, splunk counts the number of days you exceeded your license in the past 30 days, and turns off search capabilities when that number is higher than 4 or 2, depending on what version you have.  If you have multiple independent pools with separate licenses, then the other pools remain searchable even when the one pool is in violation.&lt;/P&gt;

&lt;P&gt;"Day" is calculated as per the date/time on the deployment's license master.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/AboutSplunksLicenseUsageReportView"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/AboutSplunksLicenseUsageReportView&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Here's some discussion of what you can do to stop indexing when you near the limit... but that's apparently not a strategy that most organizations seem to pursue...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/222154/how-do-i-shut-off-indexing-for-a-certain-group-who.html"&gt;https://answers.splunk.com/answers/222154/how-do-i-shut-off-indexing-for-a-certain-group-who.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Here's one with discussion and references about how to NOT pay to index uninteresting data ...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/139476/stop-indexing-at-license-cap.html"&gt;https://answers.splunk.com/answers/139476/stop-indexing-at-license-cap.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And, it turns out the simple way, referenced at this link, is to set up a universal forwarder and have THAT stop forwarding to the indexer when it hits its [thruput] limit.  The same [thruput] option may be available on the indexer.  &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/133512/how-to-limit-the-maximum-daily-indexing-volume.html"&gt;https://answers.splunk.com/answers/133512/how-to-limit-the-maximum-daily-indexing-volume.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Unfortunately, thruput is a rate in KBps, rather than MB/day, so if you throttle it to a rate that will always keep you under your license, then realistically you will NEVER use your entire license.  And, since it's a config file, to change it, you would have to restart the indexer or forwarder that you're changing.  &lt;/P&gt;

&lt;P&gt;It seems like, as a backup plan, you could have a 80%-90% warning, and at some point in the day, calculate the remaining license and throttle the indexer with thruput and a restart, then set it back again automatically after midnight, license time.  There ought to be an easier way, but that's feasible, if ugly.&lt;/P&gt;

&lt;P&gt;There is some discussion here about routing unwanted events to the nullqueue during blackout periods...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/332983/how-to-index-certain-logs-only-during-a-certain-ti.html"&gt;https://answers.splunk.com/answers/332983/how-to-index-certain-logs-only-during-a-certain-ti.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:24:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292998#M13484</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-03-23T20:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license warnings??</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292999#M13485</link>
      <description>&lt;P&gt;The quota check happens once a day, at midnight (in the time zone your license master uses). If you get a warning and correct it before midnight, then it will not count toward your rolling 30-day total. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Aboutlicenseviolations"&gt;About license violations&lt;/A&gt; in the &lt;EM&gt;Admin Manual&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-warnings/m-p/292999#M13485</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-03-23T20:26:10Z</dc:date>
    </item>
  </channel>
</rss>

