Getting Data In

Splunk Indexing is Paused Internal Grace Period?

velayudhan
New Member

Hi All 

  We are Using the Splunk Enterprise version with the Perpetual License Model with Index Capacity of 5 GB .

  We are all of sudden facing issue in the Indexing of the data when the Limit is not yet breached in the Last 30 days  .

velayudhan_1-1676173118892.png

 

 

 Can you please Guide on this case .

velayudhan_2-1676173179370.png

 

 

Labels (1)
0 Karma

velayudhan
New Member

Hi 
  Thanks for the update 

 

  Myself not able to create an Ticket on the Splunk System can you guide on the same ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @velayudhan,

at first, are you a Customer or a Splunk partner?

because you have to use a different portal:

then, if you're a customer, you must be enabled to open cases: usually when a contract is activated the customer communicate three emails of reference people to open cases, I don't know if you are enabled, otherwise, someone else in your organization must open the case.

If you're a partner, usually partners aren't enabled to open cases for the customers, because when you open a case you have to indicate the Entitlement, except if the customer enables you to open cases.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @velayudhan,

some stupid questions to understand:

when does your violation start: in the last day or before the last 30 days?

if before, you need a reset key, it isn't sufficient to wait for 30 days without violations.

Is you License master on the same server of indexers? if not, did you used IP or dns name to address the license Master from the Indexers?

If dns server, use IP because maybe there a dns resolution problem.

Anyway, you have to ask a reset key to Splunk Support.

Ciao.

Giuseppe

0 Karma

velayudhan
New Member

HI guliceo

  Thanks for the update 

  Some additional Clarity About Splunk Environment
  

  Splunk System is under License Limit of 5 GB per day and there is no means of Violation in the System

  License master is on the Splunk Search Head only

  Can you suggest a good way to reach the Splunk Team ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @velayudhan,

at first, you're using a distributed architecture, so did you configured all your Splunk servers as Forwarders and are they sending logs to indexers?

In a distributed architecture like your, it's a best practice that all the Splunk servers send theyr logs to Indexers and all server 8except Indexers) are configured as Forwarders.

Then Indexers are connected to the License Master, are you using IP address or dns name to address the License Master on Indexers? if dns, use IP.

Try this, if you not solve, you can open a case to Splunk Support on partners.splunk.com (if you're a Splunk Partners) or on www.splunk.com/en_us/about-splunk/contact-us.html#customer-support (if you're a customer).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...