Splunk Enterprise

License error

franciscof
Explorer

Hello. In the past few days i've been having an issue with my searches on my Splunk. I have an instance on which I collect some AWS logs and it had worked perfectly until last week when suddenly I started receiving this error on the job :

[indexer 1] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])
[indexer 2] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])

Also I see this error on my two indexers:

[indexer 1] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

[indexer 2] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

To clarify and reduce the scope of possible solutions I'd like to add that my license is not expired and it has not been exceeded, so I do not know what could be happening.

Could someone help me out?

Thanks in advance.

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you have exceed your daily ingesting amount at least on five days within last 30days. To resolve this you must ask from your splunk account manager a reset license to get over this situation. Also if your splunk is enough new version (6.6 or was it already 6.5?) you should ask no enforcement license to avoid this situation again. And of course you must update your license to cover your daily ingesting amount.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...