Hi,
I initially installed Splunk using the Trial Enterprise License. After converting to a Free License, I started to get the following errors:
[EventsViewer module] Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.
However, I just switched to the Free license on December 10th, the last time I can see any violation of the 500 MB would be still within the Enterprise License Trial Period. I ran a few queries and found that I had in total 5 violations over the last 2 months, all within the Enterprise Trial. Nonce since I switched to the Free License and the daily log volume is well below the 500 (normally around 150 to 200 MB) per day.
See below an example for the last 24 hours:
series sum(mb)
_audit 3.384999233
_internal 27.37375167
main 95.80099106
Any idea how to fix this without losing already indexed data?
Cheers
Sigmund
Contact support and ask them to send you a license reset key.