Installation

Splunk license violation

plissje
New Member

Hi guys,
I have a problem with Splunk and I can't really understand how to debug or solve it.
I got the following issues on my license:
http://prntscr.com/o5knj4
http://prntscr.com/o5knob
http://prntscr.com/o5kns1

I got these violations but I can't figure out what exactly is the violation or what is causing it. I'm not a Splunk expert and would appreciate some guidance into what do I do here as my searches are disabled.

Would also point out that I had a free license and I've installed a dev one several weeks ago.

Thanks!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're indexing more data than your license allows. Go to Settings->Monitoring Console->Indexing->License Usage->License Usage - Previous 30 Days. There, you can break down your usage by index or source to see where all the data is coming from. Once you find the offending data source, disable it or tune it to send less data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

plissje
New Member

I did have an issue with a free license, but I installed a dev one since.
The problem is that from what I read the new license was suppose to reset my violations but it didn't. Is that something I should be contacting support with or did I do something wrong?

Since the new license was installed I didn't violate my pool once.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...