Installation

When during the day does the daily usage allowance refresh?

jamesaarondevli
Path Finder

Hi,

When is Splunk's daily usage allowance is refreshed exactly?

Is it done at midnight relative to the time set on the host or is it refreshed by an external mechanism when usage statistics are uploaded?

I am building a mechanism for disabling indexing for a variable period of time and this information will be very useful to me.

Appreciate the information.

James.

Tags (1)
1 Solution

piebob
Splunk Employee
Splunk Employee

the checkpoint for licensing usage is performed at midnight local time on the Splunk host that is serving as your licening master.

per http://www.splunk.com/base/Documentation/latest/Admin/Aboutlicenseviolations

"If you get a violation warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period."

View solution in original post

Otacie
New Member

So what does "you have until midnight to resolve it" mean? How do you resolve it? Is there a technical solution (e.g. deleting data) or is the only solution to increase the license?

0 Karma

mw
Splunk Employee
Splunk Employee

Seeing as Splunk is a distributed architecture, and you can have many indexers, I believe that it means that you would assign more license capacity to the affected indexer. In a single server environment, I don't think it's meaningful.

0 Karma

piebob
Splunk Employee
Splunk Employee

the checkpoint for licensing usage is performed at midnight local time on the Splunk host that is serving as your licening master.

per http://www.splunk.com/base/Documentation/latest/Admin/Aboutlicenseviolations

"If you get a violation warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period."

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...