Hi,
I accidentally uploaded too much data on one day (a jsonl file) and violated the 500mb limit in place for the splunk enterprise trial. As such, it generated a pool warning:
(info) | Correct by midnight to avoid violation Learn more | This pool contains peer(s) with 1 warning(s) | splunk | auto_generated_pool_download-trial | download-trial | pool_warning_count |
After UTC passed, it generated a "permanent" record with:
Sep 29, 2025, 12:00:00 AM (2 hours ago) | This pool has exceeded its configured poolsize=524288000 bytes. A warning has been recorded for all members | splunk | auto_generated_pool_download-trial | download-trial | pool_over_quota |
However, the first warning did not clear (the info one). Will i continue to receive permanent warnings from this, or can i simply leave it and not repeat my mistake?
Hi @Ghostoverflow25
Since you have exceeded the license limit once, this is not an immediate issue. The warning message will remain visible for a period of time and will eventually clear. but ensure that you do not exceed the daily license usage limit again.
If you generate three or more warnings in a rolling 30-day period, you are in violation of your license. Splunk Enterprise continues to index your data, but you cannot search it. The warnings persist for 14 days. No reset license is available.
Here is documentation what happening when you have license violations and when those are real violations and when those are more or less informative messages.
e.g. with Splunk Free there is this limitation:
If you generate three or more warnings in a rolling 30-day period, you are in violation of your license. Splunk Enterprise continues to index your data, but you cannot search it. The warnings persist for 14 days. No reset license is available.
So after three warnings within 14 calendar days your searches have blocked until there is max two warning in 14 days.
But e.g. with Enterprise with more than 100GB/d license you can still search even you have more than 45 breaches within rolling 60 day period. Of course you must contact to Splunk and agree for additional license quota.
Hi @Ghostoverflow25 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated by all the contributors 😉
Hi @Ghostoverflow25
Since you have exceeded the license limit once, this is not an immediate issue. The warning message will remain visible for a period of time and will eventually clear. but ensure that you do not exceed the daily license usage limit again.
If you generate three or more warnings in a rolling 30-day period, you are in violation of your license. Splunk Enterprise continues to index your data, but you cannot search it. The warnings persist for 14 days. No reset license is available.
Hi @Ghostoverflow25 ,
if you exceed the license limit only one time, it isn't a problem, even if you have the warning for all the day,
Put attention only to one thing: using the Trial License, you can exceed the license only two times in 30 solar days, at the third exceeding, searches will be blocked, and anyway, after 60 days some features will expire.
Ciao.
Giuseppe
However, the first warning did not clear (the info one). ---- no need to worry.
wait for one more day, it will clear. also it is the first warning, right, so no problems at all.