Deployment Architecture

Having errors as a beginner

ryuga_075
Observer

Greetings, I have just started using splunk and I was trying to montior logs from my files section, And I am getting the following errors while doing so, help me. I am using heavy forwarder for this.

ryuga_075_0-1713438944603.png

ryuga_075_1-1713438974584.png

ryuga_075_3-1713439093043.png

 


I have added my forwarder port to 192.168.196.51:9997 and also made reciever on port 9997. I dont know where I am making mistake. Please help me with this. Thanks and Regards.

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

"Your Splunk license expired". Does it ring a bell?

ryuga_075
Observer

I have just got my licence today.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. Time to dig into the gory details of Splunk licensing.

When you have an enforcing license (either a trial, dev or "full" license not big enough to be non-enforcing), each day you exceed your daily ingestion allowance will generate a warning. If you exceed given number of warnings during a given time period (with a trial version it's 5 warnings in 30-day rolling window; with a "full" Splunk Enterprise license it's 45 warnings in 60 day), your environment will go into a "violation mode".

Most importantly - it will stop allowing you search any data other than internal indexes.

And the tricky question is that even if you add new/bigger/whatever license at this point, it will not automatically "unlock" your environment. You need to either wait for the violations to clear (for some license types) or request a special unlock license from the Splunk sales team.

So tl,dr -  if you let your Splunk run out of license, it's not as easy as "I add my freshly bought license" and it starts working again.

isoutamo
SplunkTrust
SplunkTrust
As you have gotten valid license, just ask unlock license from same source as you got your normal license.

PickleRick
SplunkTrust
SplunkTrust

Yes, thank you. I got focused on explaining why, that forgot to write what to do more explicitly.😁

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...