Installation

1 pool warning reported by 1 indexer - cannot find issue

eblackburn
Path Finder

Hello,

I installed Splunk Free a while back on a test laptop and at some point, ran into some licensing violations because of the indexing rate. At some point, I was unable to run searches.

I reinstalled Splunk Free recently, switched from Trial to Free, and when checking the Licensing page, saw this message:

1 pool warning reported by 1 indexer (Correct by midnight to avoid warning)

The problem is, according to "Volume used today", my indexing rate in the Monitoring Console, and the actual size of my indexes, I'm not anywhere remotely close to hitting 500 MB/day.

I was able to obtain a Splunk Dev license, and the issue persists after installing that. 

Now, I have pool: auto_generated_pool_enterprise, and volume used today (for example):   2 MB / 51,200 MB.

I'm seeing the same message on a Linux VM I set up on the same laptop and installed Splunk Free on.

Is this going to be something I need to worry about, or since my indexing rate is not anywhere close to 500 MB/day, I should be fine? If I need to address it, what is the best course of action? To me, it's difficult because there's not an index or data source I can narrow down and take action on. Perhaps it's because of the past issue with licensing violations.

Thanks!

 

 

Labels (1)
0 Karma

eblackburn
Path Finder

Thanks very much! I'll plan on letting the violation(s) age out. Assuming that I don't incur any new violations, hopefully things return to normal afterward. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's definitely because of the past license violations.  There are two fixes: 1) wait for the violation to time out in 30 days; or 2) ask Splunk for a Reset license.  Note that installing a new license will not reset a violation unless the new license is specifically a "reset" license.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...