Monitoring Splunk

License Pool Violation - After Search is disabled on a license pool due to 5 violations, and event generation issue is fixed, how long do I have to wait for Search re-enabling ?

pignace
New Member

Hello,
I had an issue with one of our applications which generate too many events => I have been in 5 days of license violation.
Searches are disabled as I am in a pre 6.5 Splunk Enterprise license mode.
I fixed the issue with the application so my daily volume of event is back to beeing bellow my license Gb/Day:

  • Do I have to way for 26 days ( so that the number of violations over the last 30 days goes down to less than 5 #) or is there another way of recovering access to the searchs/requests/dashboards ?
  • Will the service be available tomorrow again ?
  • Is it possible to "reset" the count ?

Thank you

Tags (1)
0 Karma

renjith_nair
Legend

@pignace,

You may contact your Splunk sales representative to get a reset key or login and raise a request with support portal

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...