All Apps and Add-ons

License Problem Splunk 4.2 Free License

cyberbkk
New Member

Hi,

I initially installed Splunk using the Trial Enterprise License. After converting to a Free License, I started to get the following errors:

[EventsViewer module] Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

However, I just switched to the Free license on December 10th, the last time I can see any violation of the 500 MB would be still within the Enterprise License Trial Period. I ran a few queries and found that I had in total 5 violations over the last 2 months, all within the Enterprise Trial. Nonce since I switched to the Free License and the daily log volume is well below the 500 (normally around 150 to 200 MB) per day.

See below an example for the last 24 hours:

series sum(mb)
_audit 3.384999233
_internal 27.37375167
main 95.80099106

Any idea how to fix this without losing already indexed data?

Cheers
Sigmund

0 Karma
1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee

Contact support and ask them to send you a license reset key.

View solution in original post

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Contact support and ask them to send you a license reset key.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...