<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Free Version License Violation help in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81651#M7305</link>
    <description>&lt;P&gt;Yes, but just be careful about the 30 days. It is a rolling 30 day window so if you had one violation and 29 days later a second violation, the countdown would restart. 29 days after your second violation you would still have 2 violations - you need to go 30 days completely free of violations to reset the count.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jun 2012 09:15:46 GMT</pubDate>
    <dc:creator>Drainy</dc:creator>
    <dc:date>2012-06-23T09:15:46Z</dc:date>
    <item>
      <title>Splunk Free Version License Violation help</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81647#M7301</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;I've been trying to get a new index built to import some IIS logs and in the process of importing and deleting content to get the formats right, I've tripped over the 500MBytes per day limit of the Free License. Trouble is, I'm hoping to back fill the final version index with some historical data but of course I'm already over the daily limit.&lt;/P&gt;

&lt;P&gt;From what I've read, the daily limit counts as one violation per day if the daily indexed volume remains at midnight. So I guess my question is, as a one off, if I continue with the backfill (bearing in mind my Splunk box is also continuing to recieve it's normal syslog traffic of around 45Mbytes per day too), will I just count as a single violation even if I'm over by a couple of hundred meg?&lt;/P&gt;

&lt;P&gt;Moving forward, the IIS boxes are generating about 90Mbyes per day between them, so I would normally be well under the 500 MBytes limit.&lt;/P&gt;

&lt;P&gt;Thanks and best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2012 10:17:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81647#M7301</guid>
      <dc:creator>martinpugh</dc:creator>
      <dc:date>2012-06-22T10:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Free Version License Violation help</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81648#M7302</link>
      <description>&lt;P&gt;hi martinpugh&lt;/P&gt;

&lt;P&gt;if I recall it right, if you hit a license violation it does not matter how much you are over the limit .... but keep in mind that each violation counts for 30 days. So 3 violation within a rolling 30 days and you cannot search your data anymore.&lt;/P&gt;

&lt;P&gt;read more &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Aboutlicenseviolations"&gt;here&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;

&lt;P&gt;MuS&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2012 11:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81648#M7302</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-06-22T11:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Free Version License Violation help</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81649#M7303</link>
      <description>&lt;P&gt;Hi MuS. That seems to be the understanding from most people too, including the Splunk partner I spoke to earlier. I've added the remaining data I wanted to get in and moving forward we will be way below the daily limit.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2012 12:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81649#M7303</guid>
      <dc:creator>martinpugh</dc:creator>
      <dc:date>2012-06-22T12:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Free Version License Violation help</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81650#M7304</link>
      <description>&lt;P&gt;Yes, the splunk license manager doesn't care whether you exceed by 10MB or 500GB, the violations count the same.  As long as you don't have 3 violations in 30 days, you'll be fine.  Just get all your data in within the 2 days.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2012 16:48:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81650#M7304</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-06-22T16:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Free Version License Violation help</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81651#M7305</link>
      <description>&lt;P&gt;Yes, but just be careful about the 30 days. It is a rolling 30 day window so if you had one violation and 29 days later a second violation, the countdown would restart. 29 days after your second violation you would still have 2 violations - you need to go 30 days completely free of violations to reset the count.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2012 09:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Free-Version-License-Violation-help/m-p/81651#M7305</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-06-23T09:15:46Z</dc:date>
    </item>
  </channel>
</rss>

