Installation

How to resolve Splunk License usage alert?

sunnyparmar
Communicator

Hi,

Can anyone tell me how to resolve a Splunk License alert problem? I have fixed the alarm at 90% so once it will reach 90% how can I solve this issue? In my graph it is showing by host, sourcetype, source, and index that which one is consuming more license? So after seeing the result how to solve this issue?

Thanks
Ankit

Labels (1)
0 Karma

drumster88
Explorer

To ensure that you don't get any license violations, monitor your license usage and make sure your license volume is sufficient to support your operational usage. If you do not have sufficient license volume you need to either increase your license or can also go for tweaking your indexing volume.

jensonthottian
Contributor

Yes. If you are using Splunk 6.0, you must have set up alert for any of the searches in the License Usage Report View. See Use the License Usage Report View in the Admin Manual. If you are using Splunk 5.x, install the Splunk on Splunk app and you will have access to the same views for your Splunk 5.x installation.

Check the $SPLUNK_HOME/var/log/splunk/license_usage.log, to check which index is more license. How to resolve the issue is check the license usage, get it increased if you are continuously reaching 90% limit.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...