Hi,
I have managed to exceed my 500MB license over the last few days after what seems to be my Unifi USG throwing 10x the amount of data it usually does at Splunk. Unfortunately, as I am locked out, I can't actually search to find out what the issue was. Is there any way to get my license unlocked other than wait 30 days?
Thanks.
If you have Splunk sales rep, they can help you with a reset key. Alternatively, if you are a paying customer, support can help you with a reset key.
the best way to bypass the violations is to backup your indexes, delete, reinstall and copy the indexes back over.
This may help you :
https://techblog.jeppson.org/2015/03/fix-splunk-lockout-after-exceeded-quota/