Monitoring Splunk

Daily indexing volume exceeded.

smolcj
Builder

Hi all, I am sorry to ask you this question, which has already answered several times before.
Do i have to remove those indexed data before midnight. i failed to do it. will it be a issue later. or the message will disappear after 14 days?
Thank you

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

You should never have to remove or lose data for a violation. If you violate your license too many times, search will be disabled. The message will go away after a while, yes.

View solution in original post

DaveSavage
Builder
0 Karma

DaveSavage
Builder

Splunk (in my experience) are not mean on this subject. If you have 3 strikes in a calendar month then it will stop searches. Spikes due to initial start up / take-on are sort of expected because it is difficult to calculate with great certainty what you need. If your problem is recurrent and persistent then talk to sales.

0 Karma

DaveSavage
Builder

@sowings - absolutely correct, a slip of imprecision on my behalf there. Amended. Thanks

0 Karma

sowings
Splunk Employee
Splunk Employee

To be clear, it stops allowing search, except on the _internal index; it doesn't stop indexing.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You should never have to remove or lose data for a violation. If you violate your license too many times, search will be disabled. The message will go away after a while, yes.

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...