Getting Data In

Free license group (Failing to Search)

albyva
Communicator

I was initially using the Splunk Enterprise Download Trial. On Feb 10th that license expired and now I'm using the Free Splunk license. I got a several Pool and Indexer warnings/violations.
Now I can't seem to search for any data without getting an error message.

How do I clear this problem so I can get back to using splunk?

Current

1 pool violation reported by 1 indexer  Correct by midnight to avoid violation Learn more
1 pool warning reported by 1 indexer    Correct by midnight to avoid violation Learn more

Permanent

6 license window warnings reported by 1 indexer     1 day ago 

Local server information

Indexer name godzilla

License expiration Feb 10, 2014 11:18:49 PM

Licensed daily volume 500 MB

Volume used today 9 MB (1.724% of quota)

Warning count 6

  1. Splunk Enterprise Download Trial
    creation_time 2013-09-26 04:00:11-04:00
    expiration_time 2014-02-10 23:18:49-05:00

  2. Splunk Forwarder
    creation_time 2010-06-20 03:00:00-04:00
    expiration_time 2038-01-18 22:14:07-05:00

  3. Splunk Free
    creation_time 2010-06-20 03:00:00-04:00
    expiration_time 2038-01-18 22:14:07-05:00

0 Karma
1 Solution

Ayn
Legend

You either wait until you've got less than 3 license warnings in a 30 day window, or contact support to get a reset license that will clear your warnings. Or you reinstall Splunk.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

View solution in original post

Ayn
Legend

You either wait until you've got less than 3 license warnings in a 30 day window, or contact support to get a reset license that will clear your warnings. Or you reinstall Splunk.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

albyva
Communicator

Thanks.. I'll contact support for a reset license.

0 Karma

kristian_kolb
Ultra Champion

Dang. You're too fast. I'm not sure that you will get a reset license for Splunk Free, though. But no harm in trying.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...