Getting Data In

Daily indexing volume limit exceeded. Error in 'UnifiedSearch': Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

vamshi_gajula
New Member

Daily indexing volume limit exceeded.
Error in 'UnifiedSearch': Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

How to resolve this issue.
Please help on this issue.

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

If you're using an enterprise license, you can contact support and they'll assist you in obtaining a reset license. If you aren't an enterprise customer, you're going to have to wait for 30 days to the license violations to clear before you're allowed to use the search functionality again. We allow 5 violations within a 30 day rolling window for enterprise customers, 3 for those using the free license.

If you go to the link I'll post below, you can find a search you can enable in the future that will alert you to any violations as they occur so that you don't end up in this situation again.

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

View solution in original post

shannongroup
Explorer

I have just received an identical error, my trial expired and I moved over to the free licence. however I have not exceeded any quota's. I just had to move from trial to free ?? Can this be rectified to allow my data to be displayed?

I'm getting

alt text

and

alt text

jbsplunk
Splunk Employee
Splunk Employee

If you're using an enterprise license, you can contact support and they'll assist you in obtaining a reset license. If you aren't an enterprise customer, you're going to have to wait for 30 days to the license violations to clear before you're allowed to use the search functionality again. We allow 5 violations within a 30 day rolling window for enterprise customers, 3 for those using the free license.

If you go to the link I'll post below, you can find a search you can enable in the future that will alert you to any violations as they occur so that you don't end up in this situation again.

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

ChrisG
Splunk Employee
Splunk Employee

...and for more information, you can read About license violations in the Admin Manual.

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...