Security

Your Splunk license expired or you have exceeded your license limit too many times

jhuebner
Explorer

So I've read this link, but I still have questions.

http://answers.splunk.com/questions/322/what-happens-when-i-exceed-my-licensed-limit

I'm not trying to index a LARGE amount of data, I'm only using SPLUNK as a front end for OSSEC. I have ~25 windows servers pointing at my OSSEC instance, and then it pointing @ SPLUNK.

If I scale back on the amount of data being indexed (change it dramatically) how long will it take to re-enable my license?

Tags (1)
0 Karma
1 Solution

jhuebner
Explorer

Else, I've found doing an "update" install clears the cache too 🙂

JLH

View solution in original post

0 Karma

xabidh
New Member

For me worked, renaming the file locate in $Splunk_Home\etc\licenses\download-trial\enttrial.lic and restart Splunk services.

0 Karma

jhuebner
Explorer

Else, I've found doing an "update" install clears the cache too 🙂

JLH

0 Karma

Simeon
Splunk Employee
Splunk Employee

The violaions are on a rolling period. So if you have just recently violated the maximum number of times, you will have to wait until one of those violations roll out of the window. Otherwise, you will need to contact your sales representative or account manager to get this addressed.

justinhart
Path Finder

It looks like you will have to be violation-free for 30 days before search will be re-enabled. You might check out this documentations: Install a License There is a section at the bottom about violations.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...