Splunk Enterprise

License error

franciscof
Explorer

Hello. In the past few days i've been having an issue with my searches on my Splunk. I have an instance on which I collect some AWS logs and it had worked perfectly until last week when suddenly I started receiving this error on the job :

[indexer 1] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])
[indexer 2] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])

Also I see this error on my two indexers:

[indexer 1] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

[indexer 2] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

To clarify and reduce the scope of possible solutions I'd like to add that my license is not expired and it has not been exceeded, so I do not know what could be happening.

Could someone help me out?

Thanks in advance.

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you have exceed your daily ingesting amount at least on five days within last 30days. To resolve this you must ask from your splunk account manager a reset license to get over this situation. Also if your splunk is enough new version (6.6 or was it already 6.5?) you should ask no enforcement license to avoid this situation again. And of course you must update your license to cover your daily ingesting amount.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...