Getting Data In

I have installed the splunk.license file but splunk is still not indexing any event?

cebo_myeza
Path Finder

I have exceeded splunk license limit too many times but now i have the splunk.license file and it's already installed and the problem now is that splunk is still not indexing any event.

please help.

0 Karma

miteshvohra
Contributor

If your download trial is over 60-day period, you cannot extend the trial duration by simply copying the license from another download trial or overwriting the existing Splunk instance with a fresh download copy. (this is most likely your case since you mentioned 'splunk.license' file name, commercial/paid enterprise license files are named differently.)

Also a download trial only allows 3 warnings before it locks down your search (except searching _internal index).

A reset license only allows to reset the count of the warnings but will not extend your trial license for another 60-day window.

0 Karma

cebo_myeza
Path Finder

Hi Miteshvohra

splunk.license is the license i got only for extending a disk space from 500mb/day to 5gb/day and my trial period is still active.

0 Karma

MuS
SplunkTrust
SplunkTrust

Indexing does not stop on a license violation, search will be disabled. Check your disk space if there is more than 5gb free, that's the default value.

0 Karma

cebo_myeza
Path Finder

hi MuS

I am using splunk free, i head 5 hard warnings before when i was still under 500MB/day and the disk space now is 5GB/day after splunk.license file installation but i am still under violation, i can not do anything.

0 Karma

MuS
SplunkTrust
SplunkTrust

Open a support case and ask for a reset license. Still indexing should not stop due to the violation, this Sound like a different problem

0 Karma

saurabh_tek
Communicator

Even i am facing the same thing, i was using 500MB/day trial and feeded in 30GB logs
index=* shows me the logs in search

but since i was getting warning so i added NFR license for 20GB valid till next 1 year (with the name splunk.license) and now looks like indexing has not started as daily quota is not utilized for today's 20 GB.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...