<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: get data splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607565#M211244</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Super ; problème résolu&lt;BR /&gt;dernière question ; dans le cas où j'ai 2 serveurs avec un dépassement de quota et que je souhaite regrouper leurs données dans un 3ème serveur&lt;BR /&gt;y a-t-il une solution?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2022 16:22:48 GMT</pubDate>
    <dc:creator>hichem_khalfi</dc:creator>
    <dc:date>2022-07-29T16:22:48Z</dc:date>
    <item>
      <title>Questions about Splunk Enterprise- What happens after 3 quota overruns, The difference between Free and Trial, etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607479#M211206</link>
      <description>&lt;P&gt;Hi please I have 3 questions regarding the splunk enterprise solution (500 mega free log)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;infact I am a student and I want to master this solution&lt;/P&gt;
&lt;P&gt;1/ after 3 quota overruns, what exactly happens? does splunk server stop receiving logs or what??&lt;/P&gt;
&lt;P&gt;2/ what is the difference between: Free license and Enterprise Trial license?&lt;/P&gt;
&lt;P&gt;3/ in case I had 2 splunk servers and I want to put one of the 2 as slave because I will need it but I only need the logs that analyzed it, what happens technically?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 15:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607479#M211206</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T15:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607480#M211207</link>
      <description>&lt;P&gt;1: Search will be disabled on all logs except the internal logs&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2: Free license is heavily reduced feature set, Enterprise trial is a trial period of the full feature set.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3: Not sure what you mean. Perhaps read up on distributed search or indexer clustering.&lt;BR /&gt;Here is the Splunk Validated Architecture document for reference.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf" target="_blank"&gt;https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607480#M211207</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-07-29T08:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607482#M211208</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165039"&gt;@chaker&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am preparing a presentation on splunk&lt;BR /&gt;I lost my first license after 3 quota overruns, and as you know if I prepare a new splunk server I lose all information on the first server&lt;BR /&gt;that's why I'm looking for a solution to have them on the second server&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607482#M211208</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T08:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607485#M211210</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;answering to your questions:&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;after three exceeding, you are in license violation so the data indexing will continue, but all searches (except the ones on _* indexes) will be disabled.&lt;/P&gt;&lt;P&gt;To restart searching, you have to receibe an unblock key from Splunk.&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;Both Free license and Trial License permit 500 MB/day of ingestion, but in Free License some features (e.g. login) are disabled, you can know which feature are disabled at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/TypesofSplunklicenses" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/TypesofSplunklicenses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3), if one server must only send logs to the other, you can install on it the Universal Forwarder (free license) and configure it to send its logs to the other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, you could see at&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/about-us/splunk-pledge/academic-license-application.html" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/about-us/splunk-pledge/academic-license-application.html&lt;/A&gt;&lt;SPAN class=""&gt;&amp;nbsp;the conditions to have a free license for acadmic scope.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607485#M211210</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T08:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607487#M211211</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- what I understand then: I can no longer use this server now because I had a test model containing a firewall and an antivirus with their own indexew, i used index= main for them&lt;/P&gt;&lt;P&gt;2- Is there a solution to complete the tests on a new splunk server without losing the existing information on the first server?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:44:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607487#M211211</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T08:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607489#M211213</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what I understand then: I can no longer use this server now because I had a test model containing a firewall and an antivirus with its own indexes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- Is there a solution to complete the tests on a new splunk server without losing the existing information on the first server?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607489#M211213</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T08:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607491#M211215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're in violation, you could ask an unblock key to Splunk to use the accademic license.&lt;/P&gt;&lt;P&gt;When you'll have (but also before it!), you'll be able to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;install Splunk on a new machine,&lt;/LI&gt;&lt;LI&gt;stop Splunk on the new and old machine,&lt;/LI&gt;&lt;LI&gt;copy indexes data ($SPLUNK_HOME/var/lib/splunk) on the new machine,&lt;/LI&gt;&lt;LI&gt;copy indexes definition (files indexes.conf) in the new machine,&lt;/LI&gt;&lt;LI&gt;restart Splunk on the new machine.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 09:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607491#M211215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T09:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607492#M211216</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to continue to use it, you have to ask to Splunk an unblock key or install a new machine and copy the old data on the new one.&lt;/P&gt;&lt;P&gt;Obviously the new installation has only three exceedings, so if you continue to have more than 500 MB/day, you'll be again in violation in three days.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 09:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607492#M211216</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T09:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607502#M211222</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is what I want to know:&lt;BR /&gt;1/ how can I have this academic license? the procedure ?&lt;BR /&gt;2/ I know I'm talking about technical stuff but I want to be sure of a few points:&lt;BR /&gt;by copying this folder ($SPLUNK_HOME/var/lib/splunk) I make sure that all the old data will be present on the new server??&lt;BR /&gt;I used only one index by default (main) so what should I do ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 10:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607502#M211222</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T10:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607513#M211227</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;about the academic license, all that I know is the link I sent bacause I didn't used it.&lt;/P&gt;&lt;P&gt;About the procedure of index moving, as described at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Indexer/Moveanindex" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Indexer/Moveanindex&lt;/A&gt;&amp;nbsp;you have to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;install on a new machine another Splunk instance using the same version,&lt;/LI&gt;&lt;LI&gt;stop both the Splunk instances,&lt;/LI&gt;&lt;LI&gt;copy the&amp;nbsp;&lt;SPAN&gt;$SPLUNK_HOME/var/lib/splunk/your index from the old in the same folder of the new one,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;copy indexes.conf where your index is defined from the old system to the new one, if the index is main, don't do this step,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;restart Splunk on the new instance.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In this way, you'll have all the old data in the new instance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 11:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607513#M211227</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T11:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607533#M211233</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please clarify me a bit more, I copied all the var/lib/splunk folder, but I didn't copy any index.conf files because I use index by default: index=main&lt;BR /&gt;but I have no results on the new server&lt;BR /&gt;where are the files indexes.conf to copy them? do you know the exact path?&lt;BR /&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 13:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607533#M211233</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T13:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607545#M211234</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if the index where you stoed your data is main, you have to copy from the old system to the new the defaultdb folder that contains all the main buckets.&lt;/P&gt;&lt;P&gt;check in $SPLUNK_HOME/etc/splunk-launch.conf if the row starting with SPLUNK_DB is active or under comment.&lt;/P&gt;&lt;P&gt;If it's commented, you have to copy the "defaultdb" folder.&lt;/P&gt;&lt;P&gt;If it's acrive (non commented), you have to copy the defaultdb folder in the path that you can find in DEFAULT_DB.&lt;/P&gt;&lt;P&gt;the indexes.conf containing main index location usually is in $SPLUNK_HOME/etc/system/local or&amp;nbsp;$SPLUNK_HOME/etc/system/default.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 15:02:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607545#M211234</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T15:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607565#M211244</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Super ; problème résolu&lt;BR /&gt;dernière question ; dans le cas où j'ai 2 serveurs avec un dépassement de quota et que je souhaite regrouper leurs données dans un 3ème serveur&lt;BR /&gt;y a-t-il une solution?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 16:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607565#M211244</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-07-29T16:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: get data splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607570#M211247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you for the first issue, please accept the solution for the other people of Community.&lt;/P&gt;&lt;P&gt;About the second question: iF the indexes are different, you can repeat the process I described for both the indexes.&lt;/P&gt;&lt;P&gt;If instead the index is the same e.g. main), merge isn't possible, so: for one of them, you can use the solution I described, for the second the only chance is to extract data in a text file and reload them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 16:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Questions-about-Splunk-Enterprise-What-happens-after-3-quota/m-p/607570#M211247</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-29T16:48:51Z</dc:date>
    </item>
  </channel>
</rss>

