Splunk can provide a one time forgiveness reset license key that is valid for 24 hours. Submit a case here and provide the following information:
The email address your enterprise license key was issued to? (Look into your $SPLUNK_HOME/etc/splunk.license for the email).
The Splunk version you need reset license key to be issued to?
NOTE: Reset license key cannot be issued for Trial or Free License. It is only applicable for Enterprise License.
You need to contact Splunk Support to obtain a reset license. You may use the web site to open a ticket at the appropriate priority level, or call the Support phone line. You should be listed with Splunk Support as one of the authorized support contacts.
It's sad... I was trying to implement some RegEx to break the content down by host/sourcetype...
I had to clean the eventdata a couple of times...
And now guess what? Licence violation! I feel like a bad boy!
Ok... Maybe I should have played with smaller logs files...
Maybe when you do a clean eventdata it should take in consideration that you will need to reindex everything...
I just read that we cannot reset a free licence. What can I do a this point? I cannot upgrade to a commercial license yet. I'm not convinced that it will be useful in my day to day tasks.
Any tips, comments, shame on me? Thanks, -P
If you're just testing, you could install a new instance and test with new data. Also, remember the licensing structure: x times busting your license in y days. This is checked ONCE A DAY. So if you need to import a lot of logs all at once for testing, that's why the busts are there. Do all your archive importing in one day, and that's one bust.
If you contact your account rep you will be able to speed up your request. Support funnels requests for reset licenses back to the account rep before issuing the license (or not.)
Or, cc your account rep on the support request for a reset license.
You need to contact Splunk Support to obtain a reset license. You may use the web site to open a ticket at the appropriate priority level, or call the Support phone line. You should be listed with Splunk Support as one of the authorized support contacts.