Splunk Search

Ran with expired trial for a few days. Do I have to wait 30 days for search to work?

rpeters_tlm
New Member

We were using the download-trial license. It expired but we didn't notice for two weeks, so we exceeded for each of those days.

Now that we have converted to the free license, do we have to wait for 30 more days for the exceeded days to roll out?

Tags (1)
0 Karma

rpeters_tlm
New Member

Thanks Duker. I have submitted a ticket.

0 Karma

theduker
New Member

I opened a ticket yesterday and received a Splunk Reset License via email from Support. Instructions are included and easy to follow.

The one thing that they don't tell you to do is after you apply this reset license you then need to go and revert back to your previous license. Manager » Licensing » Change license group -> select Free license.

The license sent to me was a 1MB enterprise license, which (of course) immediately was in violation. Though I could search and view info again. Once I change back to the Free License, the violations all went away and I am in business again.

Hope that helps.

Ted

0 Karma

theduker
New Member

I've been banging my head against the wall (and Splunk) trying to figure out how I possibly could be exceeding my license with logging 4 systems. Twas fun to troubleshoot since I cannot do query License Usage or do a License Report because Search disabled. Fun. Anyway...

I saw this post while going through the forum working on this problem and I have the same exact issue. Thanks for posting this. I never would have thought that Splunk would have flip my license over to something that was going to simply auto-violate repeatedly until locked out for 30 days (actually 30 days from the date you catch it).

I think I saw a few posts where folks were having licensing issues and it's probably exactly this.

Needless to say, I am interested in the solution as well.

I've seen mention of a License Reset. Which I am going to look into more now.

thanks,

Ted

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...