Hi Team,
Mine is SPLUNK enterprise with licensing limit upto 2GB per day. I received licensing limit has exceeded the maximum size on one fine day, to overcome the warning I cleaned up the index , after few days again i received the warning message and I cleaned up the index.Like this I cleaned up the indexes whenever I received a warning. Now when I check the license manager for more details it is showing me so far 5 messages i received previously on different dates related to exceeding the limit, though I have cleaned up. Somewhere I read that if i ignore all the warnings and if count has exceeded more than 5 then some of the search functionalities would be disabled. Now here as soon as I receive the message I would clean up the index, still the messages under license manager exists and count has exceeded more than 5. Will my search functionlities get disabled?
Need advice please!
Cheers,
Sushma.
Licensing is based on the total volume of logs you index in a day. Meaning with a license of your size any day you index more than 2 GB of logs you are going to get a warning. It doesn't matter what happens after indexing, Splunk doesn't care if you keep the data or not at that point. The warning let you know you need to take one of two actions, either purchase a larger license so you don't end up with search disabled, or stop indexing some logs so you don't incur the extra expense.
Search is disabled after exceeding your license five times in a rolling 30-day window. Some of the messages could be old or duplicate information. If search is disabled, you can reach out to Splunk Enterprise support for a temporary key to reactivate search while you work out a new arrangement.
Licensing is based on the total volume of logs you index in a day. Meaning with a license of your size any day you index more than 2 GB of logs you are going to get a warning. It doesn't matter what happens after indexing, Splunk doesn't care if you keep the data or not at that point. The warning let you know you need to take one of two actions, either purchase a larger license so you don't end up with search disabled, or stop indexing some logs so you don't incur the extra expense.
Search is disabled after exceeding your license five times in a rolling 30-day window. Some of the messages could be old or duplicate information. If search is disabled, you can reach out to Splunk Enterprise support for a temporary key to reactivate search while you work out a new arrangement.
Cleaning your index doesn't make a licensing warning go away. You get a warning for exceeding your daily indexing volume of 2GB, once that's breached for the day removing the data from your index doesn't un-breach the limit. If you exceed five of those within a 30-day window you will indeed get your search function disabled.
To avoid future warnings, look at what actually caused you to exceed your daily indexing volume. Someone might have added a chatty new source, an existing source may have been malfunctioning, or your monitored sources may just grow naturally.
http://docs.splunk.com/Documentation/Splunk/6.0.2/Admin/Aboutlicenseviolations
Thak You...!!
You can talk to Splunk Sales or your local Splunk Partner for a temporary fix, but ultimately you'll either need to cut down on those volume spikes or buy a larger license.
So far 5 messages exist and you are saying that if I exceed 5 of them in 30 days , search function would be disabled, then what am I supposed to do?
Your licensed indexing volume is per day, indeed.
One more thing indexing volume of 2GB is per day right? I mean to say that today i would index 1GB data, tomorrow i would index another 1GB which, the next day another 1GB, there's no issue right?
If your sources produce more data than before then you should get a larger license.
The exact reason is the monitored source has grown up.As you are saying that cleaning up the index doesn't breach the limit, what should I do now to avoid the indexing limit message?