Installation

When during the day does the daily usage allowance refresh?

jamesaarondevli
Path Finder

Hi,

When is Splunk's daily usage allowance is refreshed exactly?

Is it done at midnight relative to the time set on the host or is it refreshed by an external mechanism when usage statistics are uploaded?

I am building a mechanism for disabling indexing for a variable period of time and this information will be very useful to me.

Appreciate the information.

James.

Tags (1)
1 Solution

piebob
Splunk Employee
Splunk Employee

the checkpoint for licensing usage is performed at midnight local time on the Splunk host that is serving as your licening master.

per http://www.splunk.com/base/Documentation/latest/Admin/Aboutlicenseviolations

"If you get a violation warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period."

View solution in original post

Otacie
New Member

So what does "you have until midnight to resolve it" mean? How do you resolve it? Is there a technical solution (e.g. deleting data) or is the only solution to increase the license?

0 Karma

mw
Splunk Employee
Splunk Employee

Seeing as Splunk is a distributed architecture, and you can have many indexers, I believe that it means that you would assign more license capacity to the affected indexer. In a single server environment, I don't think it's meaningful.

0 Karma

piebob
Splunk Employee
Splunk Employee

the checkpoint for licensing usage is performed at midnight local time on the Splunk host that is serving as your licening master.

per http://www.splunk.com/base/Documentation/latest/Admin/Aboutlicenseviolations

"If you get a violation warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period."

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...