<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Licence free exceeded limit in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190956#M7910</link>
    <description>&lt;P&gt;The quick answer is that it is your job to ensure that you don't send too much data to Splunk and go over the free license limit. Splunk will not do it for you, and there is no way to configure it (easily) to make it so that it does.&lt;/P&gt;

&lt;P&gt;Part of it might be you doing some regular monitoring, and shutting things off when they get too chatty. Part of it might be reducing the number of your inputs. Part of it might be writing some props/transforms configuration stanzas to reduce the size of the inputs you are taking in. Part of it might be setting up multiple Splunk servers with free licenses and directing your traffic so that none of them goes over. But there is no way to tell Splunk, "Stop indexing at the free license limit."&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2015 14:27:07 GMT</pubDate>
    <dc:creator>aweitzman</dc:creator>
    <dc:date>2015-02-06T14:27:07Z</dc:date>
    <item>
      <title>Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190952#M7906</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I just have 4 servers in my splunk forwarder configuration and I exceeded the free licence.&lt;/P&gt;

&lt;P&gt;I would like configure my server to use just a free licence but no exceed the limit.&lt;/P&gt;

&lt;P&gt;Can you help me for this configuration please.&lt;/P&gt;

&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 11:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190952#M7906</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-01-23T11:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190953#M7907</link>
      <description>&lt;P&gt;Hi novoferm&lt;BR /&gt;
 For  understand this  let read Splunk-6.1.1-Admin manual &lt;BR /&gt;
 p93 (Free License)&lt;BR /&gt;
P110 (What About Violations and Warnings)&lt;BR /&gt;
 P112 (How To Avoid License Violation and correcting License warning)  &lt;/P&gt;

&lt;P&gt;NOTE : Search this manual in splunk Documentation&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 12:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190953#M7907</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2015-01-23T12:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190954#M7908</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;BR /&gt;
I'll read the manuel now&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 13:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190954#M7908</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-01-23T13:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190955#M7909</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Sorry I have read the manual but I can't resolve my licence problem.&lt;BR /&gt;
Could you help me please, to install again a free licence without exceed this limit.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 13:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190955#M7909</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-06T13:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190956#M7910</link>
      <description>&lt;P&gt;The quick answer is that it is your job to ensure that you don't send too much data to Splunk and go over the free license limit. Splunk will not do it for you, and there is no way to configure it (easily) to make it so that it does.&lt;/P&gt;

&lt;P&gt;Part of it might be you doing some regular monitoring, and shutting things off when they get too chatty. Part of it might be reducing the number of your inputs. Part of it might be writing some props/transforms configuration stanzas to reduce the size of the inputs you are taking in. Part of it might be setting up multiple Splunk servers with free licenses and directing your traffic so that none of them goes over. But there is no way to tell Splunk, "Stop indexing at the free license limit."&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 14:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190956#M7910</guid>
      <dc:creator>aweitzman</dc:creator>
      <dc:date>2015-02-06T14:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190957#M7911</link>
      <description>&lt;P&gt;OK thank you for your answer.&lt;BR /&gt;
I have reduced the number of logs in the inputs file.&lt;BR /&gt;
Now i have just 2 servers which send the windows event log to splunk forwarder.&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
[WinEventLog://Security]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
[WinEventLog://System]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;I think that the licence limit will be good now.&lt;/P&gt;

&lt;P&gt;And I wait that Splunk unlock the seach task? Or I must change anything else?&lt;/P&gt;

&lt;P&gt;Thank you a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 15:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190957#M7911</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-06T15:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190958#M7912</link>
      <description>&lt;P&gt;Yes, once you're locked out of searching, you either need to pay for a license or wait until the lock time is over in order to search again.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 15:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190958#M7912</guid>
      <dc:creator>aweitzman</dc:creator>
      <dc:date>2015-02-06T15:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190959#M7913</link>
      <description>&lt;P&gt;OK thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 15:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190959#M7913</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-06T15:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190960#M7914</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Searching is locked yet after 2 days waiting.&lt;/P&gt;

&lt;P&gt;How many time is the lock time?&lt;/P&gt;

&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 09:48:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190960#M7914</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-09T09:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190961#M7915</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;It takes 30 days to release the lock from the search.&lt;/P&gt;

&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 09:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190961#M7915</guid>
      <dc:creator>rwissSLNL</dc:creator>
      <dc:date>2015-02-09T09:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190962#M7916</link>
      <description>&lt;P&gt;It's possible to unlock before the 30 days?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 09:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190962#M7916</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-09T09:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190963#M7917</link>
      <description>&lt;P&gt;With a normal license you can request a reset license from Splunk.&lt;BR /&gt;
But because you use a free license Splunk will not give a reset key.&lt;/P&gt;

&lt;P&gt;Best solution is to buy a license key.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 10:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190963#M7917</guid>
      <dc:creator>rwissSLNL</dc:creator>
      <dc:date>2015-02-09T10:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Licence free exceeded limit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190964#M7918</link>
      <description>&lt;P&gt;OK thanks.&lt;/P&gt;

&lt;P&gt;I will wait 30 days.&lt;/P&gt;

&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 10:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Licence-free-exceeded-limit/m-p/190964#M7918</guid>
      <dc:creator>novoferm</dc:creator>
      <dc:date>2015-02-09T10:25:09Z</dc:date>
    </item>
  </channel>
</rss>

