Splunk Enterprise

License violations due to expiration and after activate we can’t receive logs in SH

pacifiquen
Explorer

Hello Team,Could you please assist me with resolving the issue of not seeing logs in SH after applying a new license? Additionally, since the Splunk license expired 5 months ago, could you kindly advise on the steps to fix this?

 

Additional information, before I often use 120gb/day and now I use 20gb/day. 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

When the license expires (as opposed to violations from exceeding ingestion limits), it locks the searching functionality. As far as I know, there is no automatic way to unlock it. You need to contact whoever you're buying your Splunk licenses from and ask them for an "unlock license" for you.

0 Karma

kiran_panchavat
Influencer

@pacifiquen 

Since your license expired 5 months ago, it’s likely that Splunk entered a state where search functionality was disabled due to license violations or expiration enforcement. Even with a new license, prior violations (e.g., exceeding the daily indexing limit multiple times before the license expired) could still block search functionality until resolved.
 
In the Splunk Web UI, go to Settings > Licensing > Usage Report and review the last 30 days (or more if available) for violations.
 
For Splunk Enterprise (versions 8.1.0+), if you exceeded your license capacity 45+ times in a 60-day period with a stack volume <100 GB, search is disabled until violations clear or a reset license is applied.
 
If violations are still active (from before the new license), you may need to wait 30 days without violations (for free licenses) or request a reset license from Splunk Support (for Enterprise licenses).
 
Contact Splunk Support via the Splunk Support Portal or call 866.GET.SPLUNK to request a reset license. Apply it via Settings > Licensing > Add License.
 
Confirm Data Ingestion
 
  • Why: If logs aren’t appearing, the issue might not be the license but rather data not reaching the Search Head.
  • Action: Verify that data is being ingested and indexed.

index=* earliest=-24h

https://www.splunk.com/en_us/resources/splunk-enterprise-license-enforcement-faq.html 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
Champion

Hi @pacifiquen 

If there has been a period of time where the license wasnt valid and was not a non-enforcement license then it may be blocked. Does it give any warning about being over the licensed limit 5 times? What is the exact error?

Either way, it sounds likely that you will need a reset license code, this can be supplied by Splunk Support and/or your Splunk account manager/team and will need to be applied to your account in order to remove the limitation.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

PickleRick
SplunkTrust
SplunkTrust

Even a non-enforcement license blocks when it's past expiry date. Been there, done that 😉 On a multi-TB non-enforcement license. Someone missed the date and didn't upload the updated license in time, we had to call Splunk for the unlock license.

Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...