Getting Data In

I have installed the splunk.license file but splunk is still not indexing any event?

cebo_myeza
Path Finder

I have exceeded splunk license limit too many times but now i have the splunk.license file and it's already installed and the problem now is that splunk is still not indexing any event.

please help.

0 Karma

miteshvohra
Contributor

If your download trial is over 60-day period, you cannot extend the trial duration by simply copying the license from another download trial or overwriting the existing Splunk instance with a fresh download copy. (this is most likely your case since you mentioned 'splunk.license' file name, commercial/paid enterprise license files are named differently.)

Also a download trial only allows 3 warnings before it locks down your search (except searching _internal index).

A reset license only allows to reset the count of the warnings but will not extend your trial license for another 60-day window.

0 Karma

cebo_myeza
Path Finder

Hi Miteshvohra

splunk.license is the license i got only for extending a disk space from 500mb/day to 5gb/day and my trial period is still active.

0 Karma

MuS
SplunkTrust
SplunkTrust

Indexing does not stop on a license violation, search will be disabled. Check your disk space if there is more than 5gb free, that's the default value.

0 Karma

cebo_myeza
Path Finder

hi MuS

I am using splunk free, i head 5 hard warnings before when i was still under 500MB/day and the disk space now is 5GB/day after splunk.license file installation but i am still under violation, i can not do anything.

0 Karma

MuS
SplunkTrust
SplunkTrust

Open a support case and ask for a reset license. Still indexing should not stop due to the violation, this Sound like a different problem

0 Karma

saurabh_tek
Communicator

Even i am facing the same thing, i was using 500MB/day trial and feeded in 30GB logs
index=* shows me the logs in search

but since i was getting warning so i added NFR license for 20GB valid till next 1 year (with the name splunk.license) and now looks like indexing has not started as daily quota is not utilized for today's 20 GB.

0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...