Getting Data In

Data indexing through the period of license violation

SRIVATSAN_IYER
Explorer

Approximately, 10 days back Splunk raised License Violation because of exceeding the quota multiple times. We have now acquired a reset license and applied it a few hours back. Things seem to be back to normal.

My question is:

Although we can see events from the past one week on Splunk, a confirmation that Splunk was continuously indexing the data throughout the period of license violation (but just not allowing the search) would be very helpful. What we would like to avoid is that the indexed data is left in an inconsistent state because of this issue. Can somebody confirm this?

Any answers for this would be highly appreciated. Thanks!

Jeff_Lightly_Sp
Communicator

Data should still have been indexed...

From the manual located at: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

During a license violation period:

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
Searches to the _internal index are not disabled. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...