Getting Data In

Daily indexing volume limit exceeded. Error in 'UnifiedSearch': Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

vamshi_gajula
New Member

Daily indexing volume limit exceeded.
Error in 'UnifiedSearch': Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

How to resolve this issue.
Please help on this issue.

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

If you're using an enterprise license, you can contact support and they'll assist you in obtaining a reset license. If you aren't an enterprise customer, you're going to have to wait for 30 days to the license violations to clear before you're allowed to use the search functionality again. We allow 5 violations within a 30 day rolling window for enterprise customers, 3 for those using the free license.

If you go to the link I'll post below, you can find a search you can enable in the future that will alert you to any violations as they occur so that you don't end up in this situation again.

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

View solution in original post

shannongroup
Explorer

I have just received an identical error, my trial expired and I moved over to the free licence. however I have not exceeded any quota's. I just had to move from trial to free ?? Can this be rectified to allow my data to be displayed?

I'm getting

alt text

and

alt text

jbsplunk
Splunk Employee
Splunk Employee

If you're using an enterprise license, you can contact support and they'll assist you in obtaining a reset license. If you aren't an enterprise customer, you're going to have to wait for 30 days to the license violations to clear before you're allowed to use the search functionality again. We allow 5 violations within a 30 day rolling window for enterprise customers, 3 for those using the free license.

If you go to the link I'll post below, you can find a search you can enable in the future that will alert you to any violations as they occur so that you don't end up in this situation again.

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

ChrisG
Splunk Employee
Splunk Employee

...and for more information, you can read About license violations in the Admin Manual.

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...