Environment - single splunk enterprise instance (v. 8.2.6) running on a RHEL 6.1 server, receiving data from multiple forwarders.
Issue - License volume has always shown as 30GB/day, for the past few years anyway. Found out today that the last license purchased (January 2022) was for 50GB/Day, but the license page is still showing 30G/day.
How do I get the correct volume showing for our licensing? I would have thought it would have been automatic, or part of the license install process.
To be fully honest with you, it's an unusual situation. Firstly, non-enforcement licenses don't come up that small typically. And secondly - license up until 2038? (effectively not time-limited one)
Yes, that end date was unexpected but I figured it was some sort of 'grace' period while licensing was worked out? Seems a little excessive, but we are a government entity, I am sure Splunk is confident they will be getting fully paid in the end.
You can check the license files in /opt/splunk/etc/license/enterprise. There you should find xml files (digitally signed so don't fiddle with them ;-)) with expiration_time (as unix timestamp) and quota.
If they agree with what your bought license terms, try restarting your splunk instance. Maybe for some reason the latest changes didn't "catch up". If they don't - it seems more like an issue for your Account Manager.
Perhaps the latest license was not installed. Have your Portal Admin sign in to the Support Portal and download the latest license.
OK, thanks, will try that. I guess I am the portal admin, the guy who set this up is long gone, I am keeping the lights on while trying to migrate to newer splunk version on newer RHEL vm. Steep learning curve.