<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Free version in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36740#M17789</link>
    <description>&lt;P&gt;Hi Kristian,&lt;/P&gt;

&lt;P&gt;I found the error i mentioned in the log file. From the licensing link i can find that i still have no alerts on licensing front, so that should be OK. &lt;/P&gt;

&lt;P&gt;With telnet, it says its connected on port 9997. That is fine too. This is getting wierd as suddenly it has stopped working.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jay&lt;/P&gt;</description>
    <pubDate>Thu, 26 Apr 2012 08:56:35 GMT</pubDate>
    <dc:creator>jaymehta18</dc:creator>
    <dc:date>2012-04-26T08:56:35Z</dc:date>
    <item>
      <title>Free version Error</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36736#M17785</link>
      <description>&lt;P&gt;I am using a free version of Splunk indexer and forwarder. I could see 2 log files on indexer which came from forwarder. But after that I could not find anything else. I made some changes on forwarder to see if indexer brings those changes. But it did not.&lt;/P&gt;
&lt;P&gt;In log file of indexer, I found this ERROR(this was the last line of log file):&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;ERROR ApplicationUpdater - Error checking for update via &lt;A href="https://splunkbase.splunk.com/api/apps:resolve/checkforupgrade:" target="test_blank"&gt;https://splunkbase.splunk.com/api/apps:resolve/checkforupgrade:&lt;/A&gt; Connect timed out.
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Is there a limit on the amount of data i could see on indexer or limit on number of files? &lt;BR /&gt;what should I do to make it work?&lt;/P&gt;
&lt;P&gt;Currently we are in POC stage and if we find this useful, we would be going for a licensed version, but for this its not letting us do anything now.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 16:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36736#M17785</guid>
      <dc:creator>jaymehta18</dc:creator>
      <dc:date>2020-09-02T16:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36737#M17786</link>
      <description>&lt;P&gt;The error message just says that your splunk instance can't connect to splunk.com. Nothing to do with your forwarding problems, unless you've accidentally changed a firewall somewhere.&lt;/P&gt;

&lt;P&gt;There are no limits for presentation of already indexed data. There are no limits regarding how many files you can monitor.&lt;/P&gt;

&lt;P&gt;The only limit is the amount of data that can be indexed per day, wich is 500 MB, both for Splunk Free and Splunk Enterprise Trial.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 08:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36737#M17786</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-04-26T08:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36738#M17787</link>
      <description>&lt;P&gt;Hi Kristian, thanks for the answer. How can i check how much amount of data has been indexed in a single day?&lt;/P&gt;

&lt;P&gt;BTW, i was not getting that error before (today morning indexing was working fine), once i started this error, i am not able to see any indexing happening.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jay&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 08:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36738#M17787</guid>
      <dc:creator>jaymehta18</dc:creator>
      <dc:date>2012-04-26T08:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36739#M17788</link>
      <description>&lt;P&gt;You can see that in the Manager page (link in the top right corner), under Licensing.&lt;/P&gt;

&lt;P&gt;Can you connect to the indexers listening IP:port from the forwarder by other means, like telnet?&lt;/P&gt;

&lt;P&gt;Have you checked the splunkd.log on the forwarder? You'll find it in /opt/splunk/var/log/splunk. That's where a lot of error messages regarding splunk will go.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 08:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36739#M17788</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-04-26T08:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36740#M17789</link>
      <description>&lt;P&gt;Hi Kristian,&lt;/P&gt;

&lt;P&gt;I found the error i mentioned in the log file. From the licensing link i can find that i still have no alerts on licensing front, so that should be OK. &lt;/P&gt;

&lt;P&gt;With telnet, it says its connected on port 9997. That is fine too. This is getting wierd as suddenly it has stopped working.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jay&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 08:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36740#M17789</guid>
      <dc:creator>jaymehta18</dc:creator>
      <dc:date>2012-04-26T08:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36741#M17790</link>
      <description>&lt;P&gt;This was getting too big for a comment, so it became an answer instead. Some things to check;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Did you find any other errors in splunkd.log?&lt;/LI&gt;
&lt;LI&gt;Are you sure that events are being created, that the forwarder could send to the indexer?&lt;/LI&gt;
&lt;LI&gt;Are you monitoring the correct file(s)?&lt;/LI&gt;
&lt;LI&gt;Do you have permissions to read the file?&lt;/LI&gt;
&lt;LI&gt;What changes have been performed since it actually worked?&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;How do you know that it isn't working? &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Have you searched for "all time"?&lt;/LI&gt;
&lt;LI&gt;Have you checked that you are sending events to the right index?&lt;/LI&gt;
&lt;LI&gt;Do you have permissions to see that index?&lt;/LI&gt;
&lt;LI&gt;Is that index searched by default?&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Make a metadata search (yes, it starts with a pipe).&lt;/P&gt;

&lt;P&gt;| metadata type=hosts | eval lastTime = strftime(lastTime, "%Y-%m-%d %H:%M:%S")&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;That should give you the time when the host sent data lastTime.&lt;/P&gt;

&lt;P&gt;That's all I can think of for now. Best of luck.&lt;/P&gt;

&lt;P&gt;/kristian&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 09:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36741#M17790</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-04-26T09:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Free version</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36742#M17791</link>
      <description>&lt;P&gt;@jaymehta18&lt;BR /&gt;
How did you solve this? The same problem suddently apperad to me earlier today...&lt;/P&gt;

&lt;P&gt;@kristian.kolb&lt;BR /&gt;
I just wonder if you have any other suggestion on how to solve this problem? &lt;/P&gt;

&lt;P&gt;I have done everything you suggested in you answer. &lt;/P&gt;

&lt;P&gt;On the search summary page, Splunk tells me that it has indexed 410 events from different sources with different sourcetypes as it should.&lt;BR /&gt;
When running a search for * Splunk tells me that it found 410 matching events, but I can't see them, and none of the fields is showing either.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2013 12:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Free-version-Error/m-p/36742#M17791</guid>
      <dc:creator>gelica</dc:creator>
      <dc:date>2013-07-24T12:25:17Z</dc:date>
    </item>
  </channel>
</rss>

