Hi,
I am seeing this warning message. Can you please help to figure out how to find the culprit or solve this?
Indexing quota exceeded for this pool, poolsz=8388608000 bytes C854CE6D-5BD0-4444-978D-1628F2E41503 auto_generated_pool_enterprise enterprise license_window
Thank You
Have a look in the manager page for licenses, it should have details on which pools have warnings, which should point you to the offending indexers.
Try using the Splunk on Splunk App to further diagnose - the Metrics tab will let you look at usage by host, source or sourcetype.
I have these installed but am not able to find what this indexer is: C854CE6D-5BD0-4444-978D-1628F2E41503
Can you please help me how can I relate the indexer with that id?
Have a look in the manager page for licenses, it should have details on which pools have warnings, which should point you to the offending indexers.
Try using the Splunk on Splunk App to further diagnose - the Metrics tab will let you look at usage by host, source or sourcetype.
Have you tried to installing Splunk on Splunk and SPlunk Depoyment Monitor. These two apps have dashboards and queries for managing your Splunk instances.