<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk _internal logs consuming license? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-internal-logs-consuming-license/m-p/236959#M21520</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have 5 GB enterprise license.We have created 8 indexes in splunk. From few days there were no data observed on created indexes,&lt;BR /&gt;
but still license has been used and we met license violation.&lt;BR /&gt;
I am not able to find any data on search head. Does that mean  the _internal logs consuming license.?&lt;BR /&gt;
Anyone faced this issue?&lt;BR /&gt;
Please suggest a solutions?&lt;/P&gt;

&lt;P&gt;Thnaks &amp;amp; Regards,&lt;BR /&gt;
Kalyani&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jan 2017 13:28:01 GMT</pubDate>
    <dc:creator>kalyanilandge</dc:creator>
    <dc:date>2017-01-12T13:28:01Z</dc:date>
    <item>
      <title>Splunk _internal logs consuming license?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-internal-logs-consuming-license/m-p/236959#M21520</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have 5 GB enterprise license.We have created 8 indexes in splunk. From few days there were no data observed on created indexes,&lt;BR /&gt;
but still license has been used and we met license violation.&lt;BR /&gt;
I am not able to find any data on search head. Does that mean  the _internal logs consuming license.?&lt;BR /&gt;
Anyone faced this issue?&lt;BR /&gt;
Please suggest a solutions?&lt;/P&gt;

&lt;P&gt;Thnaks &amp;amp; Regards,&lt;BR /&gt;
Kalyani&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 13:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-internal-logs-consuming-license/m-p/236959#M21520</guid>
      <dc:creator>kalyanilandge</dc:creator>
      <dc:date>2017-01-12T13:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk _internal logs consuming license?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-internal-logs-consuming-license/m-p/236960#M21521</link>
      <description>&lt;P&gt;All internal indexes (&lt;EM&gt;internal and all other index names starting with '&lt;/EM&gt;') do not count against your license.  If you have a license violation then you must have ingested more than 5GB into your indexes.  Use the Monitoring Console to run License Usage and Index Detail reports.  They should help identify the source of the violation.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 13:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-internal-logs-consuming-license/m-p/236960#M21521</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-01-12T13:52:38Z</dc:date>
    </item>
  </channel>
</rss>

