Getting Data In

Why am I unable to view logs after a Splunk restart?

mohinder6
New Member

So I recently hit the threshold error message. It said something like "Disk space 5000MB reached. Indexing paused". I did a temporary fix by lowering the threshold value to 200MB and it asked for a Splunk restart. I restarted Splunk through the GUI and I no longer see the threshold error while searching.
However, it's been like 30 mins now and I'm still not able to view the latest logs. Is it supposed to take some significant amount of time? If not what is the issue?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi mohinder6,

like @Sarmbrister said, you ran into a license violation and your search will stop after 3 violation in a rolling window of 30 days. Your search will resume after 30 days, read the docs http://docs.splunk.com/Documentation/Splunk/6.2.6/Admin/Aboutlicenseviolations to learn more about license violations.

Also, you're using Splunk free and I think it is still not possible or at least, very hard to get a reset key for Splunk free. So read this comment to learn about one method to reset Splunk free http://answers.splunk.com/answers/66786/free-license-reset.html#comment-66791

Hope this helps ...

cheers, MuS

Sarmbrister
Path Finder

is this the 5th time this month you have received this message? If so splunk doesn't stop indexing the data it just doesnt allow you to search any more for that day.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...