Splunk Enterprise

License Warning

jkamdar
Communicator

In last couple of days, I have seen few license alerts:

This pool has exceeded its configuration poolsize=5GB bytes. A CLE warning has been recorded for all members. 

Then I tried to look at the License Usage report by host and I see couple of issues:

1. My indexer itself it using up most of the license. 

2. My indexer is listed twice, one in all capitol (SPLUNK-SERVER1) and 2nd one, regular FQDN (splunk-server1.mydomain).

For the 1st issue, checked more and saw /var/log/audit/audit.log is the culprit. What can I do to limit it?

For the 2nd issue, I guess, I have spelled out server name differently.  Where can I check other than /opt/splunk/etc/system/local/server.conf?

Thanks for your help. 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the usage by sourcetype, index... Then check what kind of logs these are. We don't know yohr environment, we don't know your data.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...