Deployment Architecture

Splunk _internal logs consuming license?

kalyanilandge
New Member

Hi Team,

I have 5 GB enterprise license.We have created 8 indexes in splunk. From few days there were no data observed on created indexes,
but still license has been used and we met license violation.
I am not able to find any data on search head. Does that mean the _internal logs consuming license.?
Anyone faced this issue?
Please suggest a solutions?

Thnaks & Regards,
Kalyani

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

All internal indexes (internal and all other index names starting with '') do not count against your license. If you have a license violation then you must have ingested more than 5GB into your indexes. Use the Monitoring Console to run License Usage and Index Detail reports. They should help identify the source of the violation.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...