Hi all,
So, our license expired, and before the new license was uploaded there was a 45-day gap. Now I know the search is blocked but indexing continues and Splunk will revert to its trial license daily index volume.
1. My question is does Splunk still index all logs coming in?
2. Logs that were not indexed during that time can they be reindexed or what happens to them?
Thanks
Hi @woodlandrelic,
for my knowledge indexing never stops but you cannot use the logs in searches.
To be more sure, you could open a case to Splunk Support.
Thinking that you are waiting for the new license, You could also ask to your Splunk partner to give you a temporary license or a reset key.
Ciao.
Giuseppe
Thanks for the quick response. The new license has already been uploaded. I just wasn't sure if Splunk was indexing the while time.
Thanks
Hi @woodlandrelic,
indexing doesn't stop during license violation,
when you newly updated the license searches will be enabled.
I have only one doubt, that a reset key is required after a violation, I'll check it, please you do too.
Ciao.
Giuseppe