Splunk Enterprise

License error

franciscof
Explorer

Hello. In the past few days i've been having an issue with my searches on my Splunk. I have an instance on which I collect some AWS logs and it had worked perfectly until last week when suddenly I started receiving this error on the job :

[indexer 1] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])
[indexer 2] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])

Also I see this error on my two indexers:

[indexer 1] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

[indexer 2] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

To clarify and reduce the scope of possible solutions I'd like to add that my license is not expired and it has not been exceeded, so I do not know what could be happening.

Could someone help me out?

Thanks in advance.

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you have exceed your daily ingesting amount at least on five days within last 30days. To resolve this you must ask from your splunk account manager a reset license to get over this situation. Also if your splunk is enough new version (6.6 or was it already 6.5?) you should ask no enforcement license to avoid this situation again. And of course you must update your license to cover your daily ingesting amount.

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...