Deployment Architecture

Having errors as a beginner

ryuga_075
Observer

Greetings, I have just started using splunk and I was trying to montior logs from my files section, And I am getting the following errors while doing so, help me. I am using heavy forwarder for this.

ryuga_075_0-1713438944603.png

ryuga_075_1-1713438974584.png

ryuga_075_3-1713439093043.png

 


I have added my forwarder port to 192.168.196.51:9997 and also made reciever on port 9997. I dont know where I am making mistake. Please help me with this. Thanks and Regards.

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

"Your Splunk license expired". Does it ring a bell?

ryuga_075
Observer

I have just got my licence today.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. Time to dig into the gory details of Splunk licensing.

When you have an enforcing license (either a trial, dev or "full" license not big enough to be non-enforcing), each day you exceed your daily ingestion allowance will generate a warning. If you exceed given number of warnings during a given time period (with a trial version it's 5 warnings in 30-day rolling window; with a "full" Splunk Enterprise license it's 45 warnings in 60 day), your environment will go into a "violation mode".

Most importantly - it will stop allowing you search any data other than internal indexes.

And the tricky question is that even if you add new/bigger/whatever license at this point, it will not automatically "unlock" your environment. You need to either wait for the violations to clear (for some license types) or request a special unlock license from the Splunk sales team.

So tl,dr -  if you let your Splunk run out of license, it's not as easy as "I add my freshly bought license" and it starts working again.

isoutamo
SplunkTrust
SplunkTrust
As you have gotten valid license, just ask unlock license from same source as you got your normal license.

PickleRick
SplunkTrust
SplunkTrust

Yes, thank you. I got focused on explaining why, that forgot to write what to do more explicitly.😁

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...