<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Daily indexing volume exceeded. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27567#M6813</link>
    <description>&lt;P&gt;Check out: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Aboutlicenseviolations"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Aboutlicenseviolations&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2012 12:10:22 GMT</pubDate>
    <dc:creator>DaveSavage</dc:creator>
    <dc:date>2012-11-08T12:10:22Z</dc:date>
    <item>
      <title>Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27564#M6810</link>
      <description>&lt;P&gt;Hi all, I am sorry to ask you this question,  which has already answered several times before.&lt;BR /&gt;
Do i have to remove those indexed data before midnight. i failed to do it. will it be a issue later. or the message will disappear after 14 days?&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 11:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27564#M6810</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2012-11-08T11:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27565#M6811</link>
      <description>&lt;P&gt;You should never have to remove or lose data for a violation. If you violate your license too many times, search will be disabled.  The message will go away after a while, yes. &lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27565#M6811</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2012-11-08T12:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27566#M6812</link>
      <description>&lt;P&gt;Splunk (in my experience) are not mean on this subject. If you have 3 strikes in a calendar month then it will stop searches. Spikes due to initial start up / take-on are sort of expected because it is difficult to calculate with great certainty what you need. If your problem is recurrent and persistent then talk to sales.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:07:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27566#M6812</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-08T12:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27567#M6813</link>
      <description>&lt;P&gt;Check out: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Aboutlicenseviolations"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Aboutlicenseviolations&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27567#M6813</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-08T12:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27568#M6814</link>
      <description>&lt;P&gt;To be clear, it stops allowing search, except on the _internal index; it doesn't stop indexing.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27568#M6814</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-08T12:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Daily indexing volume exceeded.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27569#M6815</link>
      <description>&lt;P&gt;@sowings - absolutely correct, a slip of imprecision on my behalf there. Amended. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 15:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Daily-indexing-volume-exceeded/m-p/27569#M6815</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-08T15:13:37Z</dc:date>
    </item>
  </channel>
</rss>

