<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to avoid exceeded daily indexing volume limit  when adding new server? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92005#M9504</link>
    <description>&lt;P&gt;baalchina, did the supplied answer resolve your issue?  If so, please select it as the accepted answer.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jan 2013 14:19:53 GMT</pubDate>
    <dc:creator>jodros</dc:creator>
    <dc:date>2013-01-21T14:19:53Z</dc:date>
    <item>
      <title>how to avoid exceeded daily indexing volume limit  when adding new server?</title>
      <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92002#M9501</link>
      <description>&lt;P&gt;hello everyone,&lt;/P&gt;

&lt;P&gt;I am testing splunk, and add an iis server to splunk server. For this server had ran for years, about 12g logs in the it.&lt;/P&gt;

&lt;P&gt;So I found splunk notice me&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Daily indexing volume limit exceeded today.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;very soon.&lt;/P&gt;

&lt;P&gt;Beacuse this server cannot generate 500M logs in a single day, so in normal time everything will be ok, but what can I do if I add this server in the first time to avoid exceed daily limit?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2013 13:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92002#M9501</guid>
      <dc:creator>baalchina</dc:creator>
      <dc:date>2013-01-18T13:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid exceeded daily indexing volume limit  when adding new server?</title>
      <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92003#M9502</link>
      <description>&lt;P&gt;You are allowed to burst above your daily indexing licensing limit 5 times in 30 days with an Enterprise license.  A message will appear and remain for 14 days notifying you that you went above you daily licensing limit, but search will not be disabled.  I usually just called into support and they can turn the warning message off.  I find it is best to plan for adding servers with a large amount of backfill data, and add them all on the same day.&lt;/P&gt;

&lt;P&gt;You can also add a limits.conf file to the IIS server Splunk config to throttle the amount of logs being indexed using the "&lt;CODE&gt;maxKBps = integer&lt;/CODE&gt;" statement.  For example &lt;CODE&gt;maxKBps = 512&lt;/CODE&gt; would limit the speed of logs being send to not exceed 512 KBps.  Please notice that this is in Bytes, not bits as most networking notation uses.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2013 13:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92003#M9502</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-01-18T13:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid exceeded daily indexing volume limit  when adding new server?</title>
      <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92004#M9503</link>
      <description>&lt;P&gt;Did this answer resolve you question?  If so, please mark it as the accepted answer.  &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2013 22:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92004#M9503</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-01-18T22:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid exceeded daily indexing volume limit  when adding new server?</title>
      <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92005#M9504</link>
      <description>&lt;P&gt;baalchina, did the supplied answer resolve your issue?  If so, please select it as the accepted answer.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2013 14:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92005#M9504</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-01-21T14:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid exceeded daily indexing volume limit  when adding new server?</title>
      <link>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92006#M9505</link>
      <description>&lt;P&gt;baalchina, just checking in to see if you issue is now resolved.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2013 18:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/how-to-avoid-exceeded-daily-indexing-volume-limit-when-adding/m-p/92006#M9505</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-02-19T18:15:03Z</dc:date>
    </item>
  </channel>
</rss>

