<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: License violations help in Security</title>
    <link>https://community.splunk.com/t5/Security/License-violations-help/m-p/71819#M14008</link>
    <description>&lt;P&gt;thanks for the link, but i didn't find it of much use, as does not really tell you how to resolve the problems&lt;/P&gt;

&lt;P&gt;due the problems this app is causing i'm going to move to syslog watcher 4&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2012 19:03:05 GMT</pubDate>
    <dc:creator>mmorley</dc:creator>
    <dc:date>2012-09-26T19:03:05Z</dc:date>
    <item>
      <title>License violations help</title>
      <link>https://community.splunk.com/t5/Security/License-violations-help/m-p/71817#M14006</link>
      <description>&lt;P&gt;I sent splunk an email for advice about swapping to a free licence before the trial ran out, but never got any help and have noticed today it must have ran out recently as I now have some licence violations. I've also updated the license to the free version today and also updated the application.&lt;/P&gt;

&lt;P&gt;Under current it lists the following twice and that must correct by midnight to avoid violation&lt;/P&gt;

&lt;P&gt;1 pool warning reported by 1 indexer&lt;/P&gt;

&lt;P&gt;then under permanent it says&lt;/P&gt;

&lt;P&gt;3 license window warnings reported by 1 indexer&lt;/P&gt;

&lt;P&gt;then under local server information it reports&lt;/P&gt;

&lt;P&gt;Licensed daily volume 500mb&lt;BR /&gt;
Volume used today 0mb (0.003% of quota)&lt;BR /&gt;
Warning count 3&lt;/P&gt;

&lt;P&gt;How do i get rid of these errors without losing all my data as trying to find it through the help pages isn't very informative&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2012 18:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/License-violations-help/m-p/71817#M14006</guid>
      <dc:creator>mmorley</dc:creator>
      <dc:date>2012-09-26T18:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: License violations help</title>
      <link>https://community.splunk.com/t5/Security/License-violations-help/m-p/71818#M14007</link>
      <description>&lt;P&gt;Read this for your options:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/43083/free-license-violation-how-to-fix-and-prevent-recurrence"&gt;http://splunk-base.splunk.com/answers/43083/free-license-violation-how-to-fix-and-prevent-recurrence&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The options you have are the following since you only have 500 MB per day for free:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;buy a splunk enterprise license, and get a reset key from support. &lt;/LI&gt;
&lt;LI&gt;reinstall a new trial instance and migrate your data... every 30 days. &lt;/LI&gt;
&lt;LI&gt;limit the data volume&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;You can do this to help you manage the data volumes:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/32174/is-there-a-way-to-isolate-erratichigh-volume-sources-to-prevent-license-violations?page=1&amp;amp;focusedAnswerId=32187#32187"&gt;http://splunk-base.splunk.com/answers/32174/is-there-a-way-to-isolate-erratichigh-volume-sources-to-prevent-license-violations?page=1&amp;amp;focusedAnswerId=32187#32187&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2012 18:20:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/License-violations-help/m-p/71818#M14007</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-09-26T18:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: License violations help</title>
      <link>https://community.splunk.com/t5/Security/License-violations-help/m-p/71819#M14008</link>
      <description>&lt;P&gt;thanks for the link, but i didn't find it of much use, as does not really tell you how to resolve the problems&lt;/P&gt;

&lt;P&gt;due the problems this app is causing i'm going to move to syslog watcher 4&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2012 19:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/License-violations-help/m-p/71819#M14008</guid>
      <dc:creator>mmorley</dc:creator>
      <dc:date>2012-09-26T19:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: License violations help</title>
      <link>https://community.splunk.com/t5/Security/License-violations-help/m-p/71820#M14009</link>
      <description>&lt;P&gt;FYI, while in violation, the indexer continues to index data, but can still record new daily license warnings.&lt;/P&gt;

&lt;P&gt;With a splunk enterprise license with splunk support contract, you can ask for reset key.&lt;BR /&gt;
If you are using splunk free, you have to wait 30 days without new warnings for the violation to reset by itself.&lt;/P&gt;

&lt;P&gt;Otherwise, reinstall splunk and move the old buckets to the new install.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 16:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/License-violations-help/m-p/71820#M14009</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-09-27T16:37:20Z</dc:date>
    </item>
  </channel>
</rss>

