Deployment Architecture

Splunk _internal logs consuming license?

kalyanilandge
New Member

Hi Team,

I have 5 GB enterprise license.We have created 8 indexes in splunk. From few days there were no data observed on created indexes,
but still license has been used and we met license violation.
I am not able to find any data on search head. Does that mean the _internal logs consuming license.?
Anyone faced this issue?
Please suggest a solutions?

Thnaks & Regards,
Kalyani

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

All internal indexes (internal and all other index names starting with '') do not count against your license. If you have a license violation then you must have ingested more than 5GB into your indexes. Use the Monitoring Console to run License Usage and Index Detail reports. They should help identify the source of the violation.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...