Installation

Switched from trial to free now litsearch - Splunk license expired or you have exceeded your license

jenkinsta
Path Finder

I logged in and switched to the free version. 

The search error I am receiving:

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.
 
Licensing shows : Free license group
jenkinsta_0-1629651789973.png

 

jenkinsta_1-1629651919275.png

 

jenkinsta_2-1629651979981.png

Messages:

jenkinsta_3-1629652002421.png

Any idea to clear or reset to make work? 

Labels (1)
0 Karma

jenkinsta
Path Finder

not sure how it was exceeded as I only take in a csv with max 30 lines per day at 12:00 (covid data from the city) for a test I was doing. I did have a internet speed test that splunk injected every hour but that only contained one line of date_time,download speed. I am running on linux so may try to reinstall. or just move to another platform. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jenkinsta,

to understand what happened, you could see the License Consuprion Dashboard [Settings -- Licensing -- License Consuption] and the the graphic of the last 60 days license consuption.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jenkinsta,

this means that after the Trial license is expired, you exceeded for three times the limit of 500 MB/day of indexed logs, so the license is blocked.

You can ask a reset license to Splunk Support but it's possible that they reject your request,

In this case, if you aren't using Windows, you could try to delete the installation and restart again or install newly on a new server.

Contact your Splunk Partner, if you are a Customer or your Channel Manager, if you are a partner.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...