Splunk Enterprise

License violations due to expiration and after activate we can’t receive logs in SH

pacifiquen
Explorer

Hello Team,Could you please assist me with resolving the issue of not seeing logs in SH after applying a new license? Additionally, since the Splunk license expired 5 months ago, could you kindly advise on the steps to fix this?

 

Additional information, before I often use 120gb/day and now I use 20gb/day. 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

When the license expires (as opposed to violations from exceeding ingestion limits), it locks the searching functionality. As far as I know, there is no automatic way to unlock it. You need to contact whoever you're buying your Splunk licenses from and ask them for an "unlock license" for you.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@pacifiquen 

Since your license expired 5 months ago, it’s likely that Splunk entered a state where search functionality was disabled due to license violations or expiration enforcement. Even with a new license, prior violations (e.g., exceeding the daily indexing limit multiple times before the license expired) could still block search functionality until resolved.
 
In the Splunk Web UI, go to Settings > Licensing > Usage Report and review the last 30 days (or more if available) for violations.
 
For Splunk Enterprise (versions 8.1.0+), if you exceeded your license capacity 45+ times in a 60-day period with a stack volume <100 GB, search is disabled until violations clear or a reset license is applied.
 
If violations are still active (from before the new license), you may need to wait 30 days without violations (for free licenses) or request a reset license from Splunk Support (for Enterprise licenses).
 
Contact Splunk Support via the Splunk Support Portal or call 866.GET.SPLUNK to request a reset license. Apply it via Settings > Licensing > Add License.
 
Confirm Data Ingestion
 
  • Why: If logs aren’t appearing, the issue might not be the license but rather data not reaching the Search Head.
  • Action: Verify that data is being ingested and indexed.

index=* earliest=-24h

https://www.splunk.com/en_us/resources/splunk-enterprise-license-enforcement-faq.html 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @pacifiquen 

If there has been a period of time where the license wasnt valid and was not a non-enforcement license then it may be blocked. Does it give any warning about being over the licensed limit 5 times? What is the exact error?

Either way, it sounds likely that you will need a reset license code, this can be supplied by Splunk Support and/or your Splunk account manager/team and will need to be applied to your account in order to remove the limitation.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

PickleRick
SplunkTrust
SplunkTrust

Even a non-enforcement license blocks when it's past expiry date. Been there, done that 😉 On a multi-TB non-enforcement license. Someone missed the date and didn't upload the updated license in time, we had to call Splunk for the unlock license.

Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...