<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is the License manager reporting ingest based issues after switch to resource based license? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749216#M10962</link>
    <description>&lt;P&gt;We recently switched over from an ingest based license to a resource based (vCPU) license model in our deployment.&lt;/P&gt;&lt;P&gt;The license was successfully installed in the (dedicated) license manager however after the old license expired I noticed a bunch of warnings that the allowed volume had been exceeded.&lt;/P&gt;&lt;P&gt;Our manually specified pools have not exceeded their allocation. Though when checking the "Usage report" the available total pool license is now the "free" 500 MB/day. This is not very surprising as we no longer have a "max per day". But should the available not be "infinite" now rather then drop down to default?&lt;/P&gt;&lt;P&gt;I deleted all expired licenses and restarted the license manager and the warnings seem to have disappeared, at least for now. But the "total available license" still pushes a varning at 500 MB and up with the gauge screaming red in the "usage report"&lt;/P&gt;&lt;P&gt;My first question, how can I modify the "total available license" from the ingest based GB per day to "infinite" or any other higher number than 500 MB per day? Did I miss some step when switching from ingest based license to resource based license in the configuration of the license manager?&lt;/P&gt;&lt;P&gt;My second related question, how can I now monitor available license? There is no resource based license usage report available on the license manager?&lt;/P&gt;&lt;P&gt;All the best&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jul 2025 19:23:08 GMT</pubDate>
    <dc:creator>fatsug</dc:creator>
    <dc:date>2025-07-03T19:23:08Z</dc:date>
    <item>
      <title>Why is the License manager reporting ingest based issues after switch to resource based license?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749216#M10962</link>
      <description>&lt;P&gt;We recently switched over from an ingest based license to a resource based (vCPU) license model in our deployment.&lt;/P&gt;&lt;P&gt;The license was successfully installed in the (dedicated) license manager however after the old license expired I noticed a bunch of warnings that the allowed volume had been exceeded.&lt;/P&gt;&lt;P&gt;Our manually specified pools have not exceeded their allocation. Though when checking the "Usage report" the available total pool license is now the "free" 500 MB/day. This is not very surprising as we no longer have a "max per day". But should the available not be "infinite" now rather then drop down to default?&lt;/P&gt;&lt;P&gt;I deleted all expired licenses and restarted the license manager and the warnings seem to have disappeared, at least for now. But the "total available license" still pushes a varning at 500 MB and up with the gauge screaming red in the "usage report"&lt;/P&gt;&lt;P&gt;My first question, how can I modify the "total available license" from the ingest based GB per day to "infinite" or any other higher number than 500 MB per day? Did I miss some step when switching from ingest based license to resource based license in the configuration of the license manager?&lt;/P&gt;&lt;P&gt;My second related question, how can I now monitor available license? There is no resource based license usage report available on the license manager?&lt;/P&gt;&lt;P&gt;All the best&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 19:23:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749216#M10962</guid>
      <dc:creator>fatsug</dc:creator>
      <dc:date>2025-07-03T19:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the License manager reporting ingest based issues after switch to resource based license?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749241#M10963</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241580"&gt;@fatsug&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steps you did looks good, nothing is missing i believe.&lt;BR /&gt;When your ingest-based license expired and was removed, Splunk likely reverted to the Free license which is 500MB/day and showing the same on UI.&lt;BR /&gt;The “Usage Report” tab is only meaningful for ingest-based licenses, so ignore this report tab as i don't think Splunk have any license usage report for resource based.&lt;/P&gt;&lt;P&gt;For now to monitor resource usage better to use monitoring console only - Monitoring Console &amp;gt; Resource Usage: CPU Usage&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jul 2025 04:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749241#M10963</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-04T04:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the License manager reporting ingest based issues after switch to resource based license?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749245#M10964</link>
      <description>&lt;P&gt;I removed all expired ingest based licenses and restarted the license manager, this removed all current warnings/alerts. So far I don't see any new warnings so (fingers crossed) everything is fine. Feels good to hear that there were no obvious mistakes during install either.&lt;/P&gt;&lt;P&gt;Yes, I can monitor resource usage from the monitoring console, hopefully I can get the "conversion equation" which Splunk uses to translate load towards our allowed allocation. Would be nice to be able to check before onboarding new sources.&lt;/P&gt;&lt;P&gt;Thank you for the feedback, much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jul 2025 07:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-is-the-License-manager-reporting-ingest-based-issues-after/m-p/749245#M10964</guid>
      <dc:creator>fatsug</dc:creator>
      <dc:date>2025-07-04T07:49:28Z</dc:date>
    </item>
  </channel>
</rss>

