Installation

How do I get the correct volume showing for our licensing?

gillisme
New Member

Environment - single splunk enterprise instance (v. 8.2.6) running on a RHEL 6.1 server, receiving data from  multiple forwarders.

Issue - License volume has always shown as 30GB/day, for the past few years anyway. Found out today that the last license purchased (January 2022) was for 50GB/Day, but the license page is still showing 30G/day.

gillisme_0-1673882544945.png

How do I get the correct volume showing for our licensing? I would have thought it would have been automatic, or part of the license install process.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

To be fully honest with you, it's an unusual situation. Firstly, non-enforcement licenses don't come up that small typically. And secondly - license up until 2038? (effectively not time-limited one)

 

0 Karma

gillisme
New Member

Yes, that end date was unexpected but I figured it was some sort of 'grace' period while licensing was worked out? Seems a little excessive, but we are a government entity, I am sure Splunk is confident they will be getting fully paid in the end.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can check the license files in /opt/splunk/etc/license/enterprise. There you should find xml files (digitally signed so don't fiddle with them ;-)) with expiration_time (as unix timestamp) and quota.

If they agree with what your bought license terms, try restarting your splunk instance. Maybe for some reason the latest changes didn't "catch up". If they don't - it seems more like an issue for your Account Manager.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps the latest license was not installed.  Have your Portal Admin sign in to the Support Portal and download the latest license.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gillisme
New Member

OK, thanks, will try that. I guess I am the portal admin, the guy who set this up is long gone, I am keeping the lights on while trying to migrate to newer splunk version on newer RHEL vm. Steep learning curve.

0 Karma
Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...