All Apps and Add-ons

License Usage

ibhernandezg
New Member

Hi Good mornig we have the Splunk Enterprise in my company where i work and sudenly appers the next message Daily indexing volume limit exceeded cai I unblock temporary by mi self restarting the splunk o do i have to do something else.Thank you for you atenttion regards and have a good day.

Tags (1)
0 Karma

mbadhusha_splun
Splunk Employee
Splunk Employee

Warnings and violations occur when you exceed the maximum indexing volume allowed for your license.

If you exceed your licensed daily volume on any one calendar day, you get a violation warning. If you have 5 or more warnings on an enforced Enterprise license, or 3 warnings on a Free license, in a rolling 30-day period, you are in violation of your license.

If you get a license warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30 day period.

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license. Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days.

Please refer the below link in order to know more details about license violations.

http://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/Aboutlicenseviolations

Hope the above addresses your queries.

Cheers,
Meeran.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Restarting Splunk will not clear the license violation. A single violation should not cause problems. However, if the limit was exceeded all weekend and you can no longer conduct searches, you must contact Splunk for a special key that will reset the violation. Be sure to correct the cause of the violation first.

---
If this reply helps you, Karma would be appreciated.

ChrisG
Splunk Employee
Splunk Employee

See About license violations in the Admin Manual for more information.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...