<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Licence violation - don't understand why ? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439278#M8550</link>
    <description>&lt;P&gt;have you checked previous 30 days usage reports in the licensing console?&lt;/P&gt;</description>
    <pubDate>Sat, 11 May 2019 11:08:40 GMT</pubDate>
    <dc:creator>Sukisen1981</dc:creator>
    <dc:date>2019-05-11T11:08:40Z</dc:date>
    <item>
      <title>Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439275#M8547</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I installer a splunk few weeks ago, played 3 days on one server with 3 forwardings (oneself and 2 on others servers).&lt;/P&gt;

&lt;P&gt;I reconnect today and transform my licence (was entreprise trail) into a free licence because I have 2 warning messages :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1- Missing or malformed messages.conf stanza for LM_LICENSE:SLAVE_WARNING_COUNT_SELF 05/05/2019 à 12:18:01 
2- Missing or malformed messages.conf stanza for LM_LICENSE:SLAVE_WARNING__1557007200_ 05/05/2019 à 12:18:01
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I watch the licence usage reporting, I have 3 hard warning et I read I'm in violation.&lt;/P&gt;

&lt;P&gt;For the last 30 days, my daily licence quota was about 40%. (Licence--&amp;gt;Licence usage reporting).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal per_index_thruput earliest=-60d@d latest=now | timechart span=1d eval(sum(kb)/1024) as "Daily Indexing Volume in MB"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;--&amp;gt; give the same result : I stay below 500 M&lt;/P&gt;

&lt;P&gt;Is there somebody to help me understand what's wrong with my config ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 15:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439275#M8547</guid>
      <dc:creator>drouillot</dc:creator>
      <dc:date>2019-05-05T15:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439276#M8548</link>
      <description>&lt;P&gt;What is "a few weeks ago" ?? the Trail license is for only 60 day's&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 11:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439276#M8548</guid>
      <dc:creator>teunlaan</dc:creator>
      <dc:date>2019-05-06T11:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439277#M8549</link>
      <description>&lt;P&gt;Installed on 3rd april&lt;/P&gt;

&lt;P&gt;I paste the result of : index=_internal per_index_thruput earliest=-60d@d latest=now | timechart span=1d eval(sum(kb)/1024) as "Daily Indexing Volume in MB"&lt;/P&gt;

&lt;P&gt;2019-04-03  80.9005317687988&lt;BR /&gt;
2019-04-04  425.2479381561279&lt;BR /&gt;
2019-04-05  425.5762710571289&lt;BR /&gt;
2019-04-06  426.0857295989990&lt;BR /&gt;
2019-04-07  425.6220388412476&lt;BR /&gt;
2019-04-08  425.4880132675171&lt;BR /&gt;
2019-04-09  425.1983909606934&lt;BR /&gt;
2019-04-10  425.6022958755493&lt;BR /&gt;
2019-04-11  428.0690059661865&lt;BR /&gt;
2019-04-12  429.9727134704590&lt;BR /&gt;
2019-04-13  428.4483451843262&lt;BR /&gt;
2019-04-14  425.8094844818115&lt;BR /&gt;
2019-04-15  425.7821359634399&lt;BR /&gt;
2019-04-16  426.0781307220459&lt;BR /&gt;
2019-04-17  427.8077001571655&lt;BR /&gt;
2019-04-18  426.2353906631470&lt;BR /&gt;
2019-04-19  427.5133113861084&lt;BR /&gt;
2019-04-20  429.3108539581299&lt;BR /&gt;
2019-04-21  427.2381610870361&lt;BR /&gt;
2019-04-22  425.1466999053955&lt;BR /&gt;
2019-04-23  425.4117126464844&lt;BR /&gt;
2019-04-24  425.9489107131958&lt;BR /&gt;
2019-04-25  434.7730140686035&lt;BR /&gt;
2019-04-26  425.7145261764526&lt;BR /&gt;
2019-04-27  425.1333408355713&lt;BR /&gt;
2019-04-28  425.3632974624634&lt;BR /&gt;
2019-04-29  426.0917139053345&lt;BR /&gt;
2019-04-30  426.2192420959473&lt;BR /&gt;
2019-05-01  429.6561326980591&lt;BR /&gt;
2019-05-02  432.3099679946899&lt;BR /&gt;
2019-05-03  425.6254653930664&lt;BR /&gt;
2019-05-04  425.3939561843872&lt;BR /&gt;
2019-05-05  281.9827365875244&lt;BR /&gt;
2019-05-06  94.9014148712158&lt;/P&gt;

&lt;P&gt;I'd like to find why I have 3 critical violation error.&lt;BR /&gt;
Any suggestions ? or diagnostics to help me to understand ?&lt;BR /&gt;
Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439277#M8549</guid>
      <dc:creator>drouillot</dc:creator>
      <dc:date>2020-09-30T00:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439278#M8550</link>
      <description>&lt;P&gt;have you checked previous 30 days usage reports in the licensing console?&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 11:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439278#M8550</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-05-11T11:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439279#M8551</link>
      <description>&lt;P&gt;any updates ? Is this the first time you install Splunk on this server ?  Could be because you've already used it before... Try updating or reinstalling..&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 15:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439279#M8551</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-12T15:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Licence violation - don't understand why ?</title>
      <link>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439280#M8552</link>
      <description>&lt;P&gt;You might think that only Indexers need a license but that is not so.  When you FTR (first-time-run) Splunk, it starts a 30-day timer on the &lt;CODE&gt;Free Enterprise License&lt;/CODE&gt; no matter what role your Splunk server has.  At then end of that 30 days  you either need to reinstall or have it pointed to a license master with valid license.  Yes, this means all of your Search Heads, Heavy Forwarders, Deployers, Cluster Masters, and Monitoring Consoles.&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 21:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Licence-violation-don-t-understand-why/m-p/439280#M8552</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-12T21:42:06Z</dc:date>
    </item>
  </channel>
</rss>

