Security

Indexing Quota with Free License

cvajs
Contributor

v4.3.1 on sles 11.1

just finished a enterprise eval so when i logged in today i got some over quota messages. i made sure in Manager > Licensing that it is now Free lic model.

my daily indexing volume is ~150MB, so why these warning messages? it has thus disabled searching per the Free model, why?

Correct by midnight to avoid violation Learn more   This pool contains slave(s) with 4 warnings     myHost  auto_generated_pool_free    free    pool_warning_count

Apr 16, 2012 12:00:00 AM
(11 hours ago)  Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 15, 2012 12:00:00 AM
(1 day ago)     Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 14, 2012 12:00:00 AM
(2 days ago)    Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 13, 2012 12:00:00 AM
(3 days ago)    Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
Tags (3)
0 Karma

kaililleby
New Member

Did you ever find a solution other than waiting for 30 days?

0 Karma

Drainy
Champion

Well according to the log messages you have exceeded the indexing volume three times (which means a 30 day search shutdown).

To overcome this you will either have to wait 30 days for search to return or perhaps do a clean install and migrate over your data.

0 Karma

cvajs
Contributor

well, according the the stats for _internal index my daily indexing doesnt surpass 160MB. and, how could i exceed the quota if i had 50GB trial lic installed and then went to free, these messages came instantly right after the trial lic expired and i switched to free.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...