Installation

My Dev Splunk license was reset but still see a message that I am exceeding limits...

packet_hunter
Contributor

How long does it take after a Dev License reset before the warning messages go away. I am unlocked and able to search again, however I still receive this warning message after a restart.

License Manager: Licensing warnings will be generated today. See License Manager for details. Learn more.

I disabled all add-ons/ scripts/ apps (except Search and Reporting) I should not be ingesting anything at the moment.

Any advice on this appreciated.

Thank you

0 Karma
1 Solution

MuS
Legend

Hi packet_hunter,

the message should go away immediately for old warnings.
But if you just breached the license after the reset key was applied the warning message will stay until midnight.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
Legend

Hi packet_hunter,

the message should go away immediately for old warnings.
But if you just breached the license after the reset key was applied the warning message will stay until midnight.

Hope this helps ...

cheers, MuS

0 Karma

packet_hunter
Contributor

It appears that my reset did not clear that day's earlier breach because I used:

index=_internal source=*license_usage.log type=usage  | eval GB = b/1024/1024/1024 | eval st_idx = st.": ".idx | timechart span=1d sum(GB) as "Total GB used" by st_idx

to look for all data sources with any volume. When I found anything sending data I shut it down until I saw nothing coming in. I believe everything was disabled/shutdown before the reset. It seems that my reset did not clear everything from earlier that day and needed a nightly refresh. So I am not sure the breach that occurs the day of the reset is automatically removed.

Well at least it is cleared now. Thx

0 Karma

aalbaker
New Member

I'm having the same issue.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...