<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk license in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675740#M55327</link>
    <description>&lt;P&gt;So you mean after the restart of the Splunk, the previous data should visible.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 10:26:13 GMT</pubDate>
    <dc:creator>LogUx</dc:creator>
    <dc:date>2024-01-29T10:26:13Z</dc:date>
    <item>
      <title>Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675709#M55322</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Splunker!!&lt;/P&gt;&lt;P&gt;My Splunk Enterprise license expired on January 29th, and because of that, I have renewed the license. But I missed some events during the license expiration period. How can I get back missed events so they will show up in the below graph?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1706513002053.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29113iEB7017C7E308D956/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1706513002053.png" alt="uagraw01_1-1706513002053.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;uagraw01_1-1706513002053.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 07:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675709#M55322</guid>
      <dc:creator>LogUx</dc:creator>
      <dc:date>2024-01-29T07:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675710#M55323</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@LogUx&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it depends on how you are receiving those logs: if they are syslogs that you directly receive in Splunk (in other words not using rsyslog or syslog-ng) you missed them, for this reason is a best practice us a syslog server insted of Splunk.&lt;/P&gt;&lt;P&gt;if they come from files or wineventlog, it depends on the retention of these data in the original systems.&lt;/P&gt;&lt;P&gt;If you still have the files, you should try to read them again using the crcSal = &amp;lt;SOURCE&amp;gt; option.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 07:32:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675710#M55323</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-29T07:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675715#M55324</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;We are receiving the data through ActiveMQ.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 08:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675715#M55324</guid>
      <dc:creator>LogUx</dc:creator>
      <dc:date>2024-01-29T08:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675716#M55325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@LogUx&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know this add-on and the source, check if it's possible to send again data , otherwise they are lost.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 08:44:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675716#M55325</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-29T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675732#M55326</link>
      <description>&lt;P&gt;What report is this? Licensing errors can make your environment stop searching but they shouldn't prevent you from indexing as far as I remember.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 09:33:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675732#M55326</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-29T09:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675740#M55327</link>
      <description>&lt;P&gt;So you mean after the restart of the Splunk, the previous data should visible.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 10:26:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675740#M55327</guid>
      <dc:creator>LogUx</dc:creator>
      <dc:date>2024-01-29T10:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675742#M55328</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@LogUx&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you were in License Violation, Indexing didn't stop, only searching was stopped, so you should have all the logs, also in the no licensing period.&lt;/P&gt;&lt;P&gt;If you haven't (as from your screenshot), there is another reason for this, as I described in my answer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 10:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-license/m-p/675742#M55328</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-29T10:29:09Z</dc:date>
    </item>
  </channel>
</rss>

