Installation

Index Limit Reached

pmgsupport
New Member

I am a new user and just today created a new @indows 2008 R2 server and installed using the following script:

msiexec.exe /i splunk-6.0-182037-x64-release.msi AGREETOLICENSE=Yes INSTALLDIR="E:\Program Files\Splunk" WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 REGISTRYCHECK_LM=1 REGISTRYCHECK_BASELINE_LM=1 WMICHECK_CPUTIME=1 WMICHECK_LOCALDISK=1 WMICHECK_FREEDISK=1 WMICHECK_MEMORY=1 LOGON_USERNAME="DOM\DOMSPLUNK" LOGON_PASSWORD="asd34I2Wy" LAUNCHSPLUNK=1 INSTALL_SHORTCUT=1 /quiet

As soon as my install was successfully completed I logged into the web interface and noticed that my limit was reached due to the monitoring of my local event logs.

While I do not really have a good understanding of what the limit really means and how it effects my searches I would appreciate any advice. So far I have about 10 minutes of post install experience with the product.

Looks cool though.
-Ajay

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

Since this was a fresh Splunk install on machine that has been running for some time, I guess that the combined amount of all logs that you monitor exceed the 500MB/day limit that the 'Free' and 'Download Trial' licenses allow. So the first time Splunk starts up, it will consume all historical log entries for the specified log sources, and depending on your configuration for log file retention, that can be a lot.

Most likely, this will not be the case in the days to come, unless you have a very busy system. And you are allowed to have 3 license warnings within the last 30 days (rolling).

BTW, Welcome to Splunk! Hope you enjoy the ride.

/K

lukejadamec
Super Champion

In Splunk/etc/apps/MSICreated/local you should find an inputs.conf file that will contain the configuration for monitoring your local event logs. Change disable from 0 to 1 for the events you don't want, and restart Splunk.

0 Karma

pmgsupport
New Member

Thank you Kristian for your quick response. I will limit my inputs and hope that the indexer is good to me.

Is there a method for me to remove the data collected from the local event log? The local machine (splunk server) event log data is not of interest to me.
-Ajay

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...