All Apps and Add-ons

License Usage

ibhernandezg
New Member

Hi Good mornig we have the Splunk Enterprise in my company where i work and sudenly appers the next message Daily indexing volume limit exceeded cai I unblock temporary by mi self restarting the splunk o do i have to do something else.Thank you for you atenttion regards and have a good day.

Tags (1)
0 Karma

mbadhusha_splun
Splunk Employee
Splunk Employee

Warnings and violations occur when you exceed the maximum indexing volume allowed for your license.

If you exceed your licensed daily volume on any one calendar day, you get a violation warning. If you have 5 or more warnings on an enforced Enterprise license, or 3 warnings on a Free license, in a rolling 30-day period, you are in violation of your license.

If you get a license warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30 day period.

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license. Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days.

Please refer the below link in order to know more details about license violations.

http://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/Aboutlicenseviolations

Hope the above addresses your queries.

Cheers,
Meeran.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Restarting Splunk will not clear the license violation. A single violation should not cause problems. However, if the limit was exceeded all weekend and you can no longer conduct searches, you must contact Splunk for a special key that will reset the violation. Be sure to correct the cause of the violation first.

---
If this reply helps you, Karma would be appreciated.

ChrisG
Splunk Employee
Splunk Employee

See About license violations in the Admin Manual for more information.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...