Installation

Licensing Issue

sushma7
Path Finder

Hi Team,

Mine is SPLUNK enterprise with licensing limit upto 2GB per day. I received licensing limit has exceeded the maximum size on one fine day, to overcome the warning I cleaned up the index , after few days again i received the warning message and I cleaned up the index.Like this I cleaned up the indexes whenever I received a warning. Now when I check the license manager for more details it is showing me so far 5 messages i received previously on different dates related to exceeding the limit, though I have cleaned up. Somewhere I read that if i ignore all the warnings and if count has exceeded more than 5 then some of the search functionalities would be disabled. Now here as soon as I receive the message I would clean up the index, still the messages under license manager exists and count has exceeded more than 5. Will my search functionlities get disabled?

Need advice please!

Cheers,
Sushma.

Tags (1)
0 Karma
1 Solution

kaufmanm
Communicator

Licensing is based on the total volume of logs you index in a day. Meaning with a license of your size any day you index more than 2 GB of logs you are going to get a warning. It doesn't matter what happens after indexing, Splunk doesn't care if you keep the data or not at that point. The warning let you know you need to take one of two actions, either purchase a larger license so you don't end up with search disabled, or stop indexing some logs so you don't incur the extra expense.

Search is disabled after exceeding your license five times in a rolling 30-day window. Some of the messages could be old or duplicate information. If search is disabled, you can reach out to Splunk Enterprise support for a temporary key to reactivate search while you work out a new arrangement.

View solution in original post

0 Karma

kaufmanm
Communicator

Licensing is based on the total volume of logs you index in a day. Meaning with a license of your size any day you index more than 2 GB of logs you are going to get a warning. It doesn't matter what happens after indexing, Splunk doesn't care if you keep the data or not at that point. The warning let you know you need to take one of two actions, either purchase a larger license so you don't end up with search disabled, or stop indexing some logs so you don't incur the extra expense.

Search is disabled after exceeding your license five times in a rolling 30-day window. Some of the messages could be old or duplicate information. If search is disabled, you can reach out to Splunk Enterprise support for a temporary key to reactivate search while you work out a new arrangement.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Cleaning your index doesn't make a licensing warning go away. You get a warning for exceeding your daily indexing volume of 2GB, once that's breached for the day removing the data from your index doesn't un-breach the limit. If you exceed five of those within a 30-day window you will indeed get your search function disabled.

To avoid future warnings, look at what actually caused you to exceed your daily indexing volume. Someone might have added a chatty new source, an existing source may have been malfunctioning, or your monitored sources may just grow naturally.

http://docs.splunk.com/Documentation/Splunk/6.0.2/Admin/Aboutlicenseviolations

sushma7
Path Finder

Thak You...!!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can talk to Splunk Sales or your local Splunk Partner for a temporary fix, but ultimately you'll either need to cut down on those volume spikes or buy a larger license.

sushma7
Path Finder

So far 5 messages exist and you are saying that if I exceed 5 of them in 30 days , search function would be disabled, then what am I supposed to do?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Your licensed indexing volume is per day, indeed.

0 Karma

sushma7
Path Finder

One more thing indexing volume of 2GB is per day right? I mean to say that today i would index 1GB data, tomorrow i would index another 1GB which, the next day another 1GB, there's no issue right?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your sources produce more data than before then you should get a larger license.

0 Karma

sushma7
Path Finder

The exact reason is the monitored source has grown up.As you are saying that cleaning up the index doesn't breach the limit, what should I do now to avoid the indexing limit message?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...