Installation

What can I do to prevent a 2nd license violation within my 30 day rolling period?

fziegler
New Member

Today at 5pm. I triggered my 1st license violation of my 30day rolling period. i am currently at 110% of my 10GB quota. Is there anything I can do between now and midnight to clear this up so I won't get "pegged" ?

thanks.

Tags (1)
0 Karma

lguinn2
Legend

No, there is nothing that you can do. You indexed more than your license. There is no way to "unindex" data.
However, if you had multiple license pools, and another pool had available license, you could shift the license between pools and make a pool violation go away.

But if your total license is 10 GB and you indexed 11 GB - you will get a violation.

The important question is "why did this happen"? Splunk has some built-in reports that help you examine your license usage. I would take a close look at those and see if you can identify the reason that you are over quota. In Splunk 6, you can find the Splunk License Usage Report View under Settings > License

If you are using an older version of Splunk, there are a number of apps and reports that will help you break down your usage. I recommend the Splunk on Splunk app (SOS) for all versions of Splunk.

If you can't figure it out, or need help deciding what to do next, please

  • ask more questions in this forum
  • open a support ticket

No one wants to get enough violations to lock up their Splunk search!

Hopefully, this was an anomaly and won't happen again anytime soon. But you should do your research and be sure...

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...