Installation

how to avoid exceeded daily indexing volume limit when adding new server?

baalchina
New Member

hello everyone,

I am testing splunk, and add an iis server to splunk server. For this server had ran for years, about 12g logs in the it.

So I found splunk notice me

Daily indexing volume limit exceeded today.

very soon.

Beacuse this server cannot generate 500M logs in a single day, so in normal time everything will be ok, but what can I do if I add this server in the first time to avoid exceed daily limit?

Thanks.

Tags (1)
0 Karma

jodros
Builder

You are allowed to burst above your daily indexing licensing limit 5 times in 30 days with an Enterprise license. A message will appear and remain for 14 days notifying you that you went above you daily licensing limit, but search will not be disabled. I usually just called into support and they can turn the warning message off. I find it is best to plan for adding servers with a large amount of backfill data, and add them all on the same day.

You can also add a limits.conf file to the IIS server Splunk config to throttle the amount of logs being indexed using the "maxKBps = integer" statement. For example maxKBps = 512 would limit the speed of logs being send to not exceed 512 KBps. Please notice that this is in Bytes, not bits as most networking notation uses.

jodros
Builder

baalchina, just checking in to see if you issue is now resolved.

thanks

0 Karma

jodros
Builder

baalchina, did the supplied answer resolve your issue? If so, please select it as the accepted answer.

Thanks

0 Karma

jodros
Builder

Did this answer resolve you question? If so, please mark it as the accepted answer.

Thanks

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...