<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic License violations due to expiration and after activate we can’t receive logs in SH in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741574#M21841</link>
    <description>&lt;P&gt;Hello Team,&lt;SPAN&gt;Could you please assist me with resolving the issue of not seeing logs in SH after applying a new license? Additionally, since the Splunk license expired 5 months ago, could you kindly advise on the steps to fix this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Additional information, before I often use 120gb/day and now I use 20gb/day.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Mar 2025 12:34:59 GMT</pubDate>
    <dc:creator>pacifiquen</dc:creator>
    <dc:date>2025-03-12T12:34:59Z</dc:date>
    <item>
      <title>License violations due to expiration and after activate we can’t receive logs in SH</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741574#M21841</link>
      <description>&lt;P&gt;Hello Team,&lt;SPAN&gt;Could you please assist me with resolving the issue of not seeing logs in SH after applying a new license? Additionally, since the Splunk license expired 5 months ago, could you kindly advise on the steps to fix this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Additional information, before I often use 120gb/day and now I use 20gb/day.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 12:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741574#M21841</guid>
      <dc:creator>pacifiquen</dc:creator>
      <dc:date>2025-03-12T12:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: License violations due to expiration and after activate we can’t receive logs in SH</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741575#M21842</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250798"&gt;@pacifiquen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there has been a period of time where the license wasnt valid and was not a non-enforcement license then it may be blocked. Does it give any warning about being over the licensed limit 5 times? What is the exact error?&lt;/P&gt;&lt;P&gt;Either way, it sounds likely that you will need a reset license code, this can be supplied by Splunk Support and/or your Splunk account manager/team and will need to be applied to your account in order to remove the limitation.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 12:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741575#M21842</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-12T12:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: License violations due to expiration and after activate we can’t receive logs in SH</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741654#M21845</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250798"&gt;@pacifiquen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Since&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;your&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;license&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;expired&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;5&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;months&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ago,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;it’s&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;likely&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;entered&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;state&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;where&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;search&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;functionality&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;disabled&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;due&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;license&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;violations&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;or&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;expiration&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;enforcement.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Even with a new license, prior violations (e.g., exceeding the daily indexing limit multiple times before the license expired) could still block search functionality until resolved.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In the Splunk Web UI, go to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Licensing &amp;gt; Usage Report&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; and review the last 30 days (or more if available) for violations.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;For Splunk Enterprise (versions 8.1.0+), if you exceeded your license capacity 45+ times in a 60-day period with a stack volume &amp;lt;100 GB, search is disabled until violations clear or a reset license is applied.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;If violations are still active (from before the new license), you may need to wait 30 days without violations (for free licenses) or request a &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;reset license&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; from Splunk Support (for Enterprise licenses).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Contact Splunk Support via the &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="" href="https://www.splunk.com/en_us/support-and-services.html" target="_blank" rel="noopener noreferrer nofollow"&gt;&lt;SPAN class=""&gt;Splunk Support Portal&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; or call 866.GET.SPLUNK to request a reset license. Apply it via &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Licensing &amp;gt; Add License&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Confirm Data Ingestion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Why&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: If logs aren’t appearing, the issue might not be the license but rather data not reaching the Search Head.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Action&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Verify that data is being ingested and indexed.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;index=* earliest=-24h&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/resources/splunk-enterprise-license-enforcement-faq.html" target="_blank"&gt;https://www.splunk.com/en_us/resources/splunk-enterprise-license-enforcement-faq.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Mar 2025 07:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741654#M21845</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-13T07:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: License violations due to expiration and after activate we can’t receive logs in SH</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741657#M21846</link>
      <description>&lt;P&gt;When the license expires (as opposed to violations from exceeding ingestion limits), it locks the searching functionality. As far as I know, there is no automatic way to unlock it. You need to contact whoever you're buying your Splunk licenses from and ask them for an "unlock license" for you.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 07:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741657#M21846</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-13T07:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: License violations due to expiration and after activate we can’t receive logs in SH</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741658#M21847</link>
      <description>&lt;P&gt;Even a non-enforcement license blocks when it's past expiry date. Been there, done that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; On a multi-TB non-enforcement license. Someone missed the date and didn't upload the updated license in time, we had to call Splunk for the unlock license.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 07:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-violations-due-to-expiration-and-after-activate-we-can-t/m-p/741658#M21847</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-13T07:30:35Z</dc:date>
    </item>
  </channel>
</rss>

