Deployment Architecture

Having errors as a beginner

ryuga_075
Observer

Greetings, I have just started using splunk and I was trying to montior logs from my files section, And I am getting the following errors while doing so, help me. I am using heavy forwarder for this.

ryuga_075_0-1713438944603.png

ryuga_075_1-1713438974584.png

ryuga_075_3-1713439093043.png

 


I have added my forwarder port to 192.168.196.51:9997 and also made reciever on port 9997. I dont know where I am making mistake. Please help me with this. Thanks and Regards.

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

"Your Splunk license expired". Does it ring a bell?

ryuga_075
Observer

I have just got my licence today.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. Time to dig into the gory details of Splunk licensing.

When you have an enforcing license (either a trial, dev or "full" license not big enough to be non-enforcing), each day you exceed your daily ingestion allowance will generate a warning. If you exceed given number of warnings during a given time period (with a trial version it's 5 warnings in 30-day rolling window; with a "full" Splunk Enterprise license it's 45 warnings in 60 day), your environment will go into a "violation mode".

Most importantly - it will stop allowing you search any data other than internal indexes.

And the tricky question is that even if you add new/bigger/whatever license at this point, it will not automatically "unlock" your environment. You need to either wait for the violations to clear (for some license types) or request a special unlock license from the Splunk sales team.

So tl,dr -  if you let your Splunk run out of license, it's not as easy as "I add my freshly bought license" and it starts working again.

isoutamo
SplunkTrust
SplunkTrust
As you have gotten valid license, just ask unlock license from same source as you got your normal license.

PickleRick
SplunkTrust
SplunkTrust

Yes, thank you. I got focused on explaining why, that forgot to write what to do more explicitly.😁

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...