Getting Data In

I'm receiving "Indexing quota exceeded" even my daily logs are about 300MB size

vitaly_il
New Member

I'm receiving daily alert about Splunk license even my daily logs volume is under 500MB - about 300MB.
Any ideas?

TIA, Vitaly

See alerts below:

Severity Time Message Indexer Pool Stack Category
Jan 8, 2013 12:00:00 AM
(3 hours ago) Indexing quota exceeded for this pool, poolsz=524288000 bytes splunk-server auto_generated_pool_download-trial download-trial license_window
Jan 7, 2013 12:00:00 AM
(1 day ago) Indexing quota exceeded for this pool, poolsz=524288000 bytes ssplunk-server auto_generated_pool_download-trial download-trial license_window

0 Karma

stephane_cyrill
Builder

Hi,
The alert message is clear.
Your license is simply make up of pools with individual quotas. So when one the pool exceed his quota or for any license violation in any pool, splunk must report it to you.
NOTE that that license violation only affect that pool and the other pools are still functioning.

The strategy of dividing you license is very interesting because in your deployment you can assign a team or a machine to a license pool, doing so if they if they exceed their quota they will be stop from consuming more.

0 Karma

vitaly_il
New Member

it's uncompressed Jboss logs.

0 Karma

Ayn
Legend

300MB compressed or uncompressed?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...