Splunk Enterprise

License error

franciscof
Explorer

Hello. In the past few days i've been having an issue with my searches on my Splunk. I have an instance on which I collect some AWS logs and it had worked perfectly until last week when suddenly I started receiving this error on the job :

[indexer 1] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])
[indexer 2] restricting search to internal indexes only (reason: [DISABLED_DUE_TO_VIOLATION,0])

Also I see this error on my two indexers:

[indexer 1] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

[indexer 2] Streamed search execute failed because: Error in "litsearch" command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK..

To clarify and reduce the scope of possible solutions I'd like to add that my license is not expired and it has not been exceeded, so I do not know what could be happening.

Could someone help me out?

Thanks in advance.

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you have exceed your daily ingesting amount at least on five days within last 30days. To resolve this you must ask from your splunk account manager a reset license to get over this situation. Also if your splunk is enough new version (6.6 or was it already 6.5?) you should ask no enforcement license to avoid this situation again. And of course you must update your license to cover your daily ingesting amount.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...