All Apps and Add-ons

Daily indexing volume limit exceeded today - Splunk no longer indexing?

earixson
Engager

I have a trial license on Splunk 6.1.1. I added a new data source today and went over the trial license quota.

Now the number of events indexed is not going up and any searches I do aren't returning any NEW events.

I've read over the relevant sections of the manual and the other questions about licensing here and this doesn't seem to be expected behavior. This is the first license warning we've had.

0 Karma

lukejadamec
Super Champion

Glad to hear you got it working. I don't recall ever seeing an index go bad without errors.

0 Karma

earixson
Engager

Thanks for the pointer. You were correct; it was NOT license related , that was just a coincidence. Something (not sure what) is wrong with the index I was using. Pointing my inputs to the main index resolved the issue.

0 Karma

lukejadamec
Super Champion

Are you seeing any errors in the splunkd.log?
It sounds like either your forwarder went off line, or some other failure occured. The problem you're having is not related to licensing.

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...