Splunk Enterprise

License Warning

jkamdar
Communicator

In last couple of days, I have seen few license alerts:

This pool has exceeded its configuration poolsize=5GB bytes. A CLE warning has been recorded for all members. 

Then I tried to look at the License Usage report by host and I see couple of issues:

1. My indexer itself it using up most of the license. 

2. My indexer is listed twice, one in all capitol (SPLUNK-SERVER1) and 2nd one, regular FQDN (splunk-server1.mydomain).

For the 1st issue, checked more and saw /var/log/audit/audit.log is the culprit. What can I do to limit it?

For the 2nd issue, I guess, I have spelled out server name differently.  Where can I check other than /opt/splunk/etc/system/local/server.conf?

Thanks for your help. 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the usage by sourcetype, index... Then check what kind of logs these are. We don't know yohr environment, we don't know your data.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...