We recently switched over from an ingest based license to a resource based (vCPU) license model in our deployment.
The license was successfully installed in the (dedicated) license manager however after the old license expired I noticed a bunch of warnings that the allowed volume had been exceeded.
Our manually specified pools have not exceeded their allocation. Though when checking the "Usage report" the available total pool license is now the "free" 500 MB/day. This is not very surprising as we no longer have a "max per day". But should the available not be "infinite" now rather then drop down to default?
I deleted all expired licenses and restarted the license manager and the warnings seem to have disappeared, at least for now. But the "total available license" still pushes a varning at 500 MB and up with the gauge screaming red in the "usage report"
My first question, how can I modify the "total available license" from the ingest based GB per day to "infinite" or any other higher number than 500 MB per day? Did I miss some step when switching from ingest based license to resource based license in the configuration of the license manager?
My second related question, how can I now monitor available license? There is no resource based license usage report available on the license manager?
All the best
Steps you did looks good, nothing is missing i believe.
When your ingest-based license expired and was removed, Splunk likely reverted to the Free license which is 500MB/day and showing the same on UI.
The “Usage Report” tab is only meaningful for ingest-based licenses, so ignore this report tab as i don't think Splunk have any license usage report for resource based.
For now to monitor resource usage better to use monitoring console only - Monitoring Console > Resource Usage: CPU Usage
Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
Steps you did looks good, nothing is missing i believe.
When your ingest-based license expired and was removed, Splunk likely reverted to the Free license which is 500MB/day and showing the same on UI.
The “Usage Report” tab is only meaningful for ingest-based licenses, so ignore this report tab as i don't think Splunk have any license usage report for resource based.
For now to monitor resource usage better to use monitoring console only - Monitoring Console > Resource Usage: CPU Usage
Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
I removed all expired ingest based licenses and restarted the license manager, this removed all current warnings/alerts. So far I don't see any new warnings so (fingers crossed) everything is fine. Feels good to hear that there were no obvious mistakes during install either.
Yes, I can monitor resource usage from the monitoring console, hopefully I can get the "conversion equation" which Splunk uses to translate load towards our allowed allocation. Would be nice to be able to check before onboarding new sources.
Thank you for the feedback, much appreciated.