Getting Data In

Splunk licensing pool warning not clearing

Ghostoverflow25
Engager

Hi,

I accidentally uploaded too much data on one day (a jsonl file) and violated the 500mb limit in place for the splunk enterprise trial. As such, it generated a pool warning:

(info)Correct by midnight to avoid violation Learn moreThis pool contains peer(s) with 1 warning(s)splunkauto_generated_pool_download-trialdownload-trialpool_warning_count

After UTC passed, it generated a "permanent" record with:

Sep 29, 2025, 12:00:00 AM
(2 hours ago)
This pool has exceeded its configured poolsize=524288000 bytes. A warning has been recorded for all memberssplunkauto_generated_pool_download-trialdownload-trialpool_over_quota

However, the first warning did not clear (the info one). Will i continue to receive permanent warnings from this, or can i simply leave it and not repeat my mistake?

Labels (2)
0 Karma
1 Solution

thahir
Communicator

Hi @Ghostoverflow25 

Since you have exceeded the license limit once, this is not an immediate issue. The warning message will remain visible for a period of time and will eventually clear. but ensure that you do not exceed the daily license usage limit again.

If you generate three or more warnings in a rolling 30-day period, you are in violation of your license. Splunk Enterprise continues to index your data, but you cannot search it. The warnings persist for 14 days. No reset license is available.

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ghostoverflow25 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

thahir
Communicator

Hi @Ghostoverflow25 

Since you have exceeded the license limit once, this is not an immediate issue. The warning message will remain visible for a period of time and will eventually clear. but ensure that you do not exceed the daily license usage limit again.

If you generate three or more warnings in a rolling 30-day period, you are in violation of your license. Splunk Enterprise continues to index your data, but you cannot search it. The warnings persist for 14 days. No reset license is available.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ghostoverflow25 ,

if you exceed the license limit only one time, it isn't a problem, even if you have the warning for all the day,

Put attention only to one thing: using the Trial License, you can exceed the license only two times in 30 solar days, at the third exceeding, searches will be blocked, and anyway, after 60 days some features will expire.

Ciao.

Giuseppe

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Ghostoverflow25 

However, the first warning did not clear (the info one). ---- no need to worry. 

wait for one more day, it will clear. also it is the first warning, right, so no problems at all. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...