Alerting

Delay log ingestion after License update

spodda01da
Path Finder

Hello All,

I am having an issue where log ingestion have delay for hours after I updated Splunk License.

License got expired and after 24 hours we got a renewed license but after updating it the log are coming very late by few hours.

Before reaching out to Splunk, I wanted to check if its because of the new License or may

Labels (1)
0 Karma

spodda01da
Path Finder

Thank you! it seems restarting splunk services has fixed the issue.

0 Karma

codebuilder
SplunkTrust
SplunkTrust

Also, if you utilize scheduled searches those would be impacted, and depending on the scheduling of those you might see delayed results. Use a real time search to validate or manually kick off any saved searches.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
SplunkTrust
SplunkTrust

Indexing should not be affected by an expired license, only searching.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...