Installation

How to resolve Splunk License usage alert?

sunnyparmar
Communicator

Hi,

Can anyone tell me how to resolve a Splunk License alert problem? I have fixed the alarm at 90% so once it will reach 90% how can I solve this issue? In my graph it is showing by host, sourcetype, source, and index that which one is consuming more license? So after seeing the result how to solve this issue?

Thanks
Ankit

Labels (1)
0 Karma

drumster88
Explorer

To ensure that you don't get any license violations, monitor your license usage and make sure your license volume is sufficient to support your operational usage. If you do not have sufficient license volume you need to either increase your license or can also go for tweaking your indexing volume.

jensonthottian
Contributor

Yes. If you are using Splunk 6.0, you must have set up alert for any of the searches in the License Usage Report View. See Use the License Usage Report View in the Admin Manual. If you are using Splunk 5.x, install the Splunk on Splunk app and you will have access to the same views for your Splunk 5.x installation.

Check the $SPLUNK_HOME/var/log/splunk/license_usage.log, to check which index is more license. How to resolve the issue is check the license usage, get it increased if you are continuously reaching 90% limit.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...