Splunk Enterprise

License violations due to expiration and after activate we can’t receive logs in SH

pacifiquen
Explorer

Hello Team,Could you please assist me with resolving the issue of not seeing logs in SH after applying a new license? Additionally, since the Splunk license expired 5 months ago, could you kindly advise on the steps to fix this?

 

Additional information, before I often use 120gb/day and now I use 20gb/day. 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

When the license expires (as opposed to violations from exceeding ingestion limits), it locks the searching functionality. As far as I know, there is no automatic way to unlock it. You need to contact whoever you're buying your Splunk licenses from and ask them for an "unlock license" for you.

0 Karma

kiran_panchavat
Champion

@pacifiquen 

Since your license expired 5 months ago, it’s likely that Splunk entered a state where search functionality was disabled due to license violations or expiration enforcement. Even with a new license, prior violations (e.g., exceeding the daily indexing limit multiple times before the license expired) could still block search functionality until resolved.
 
In the Splunk Web UI, go to Settings > Licensing > Usage Report and review the last 30 days (or more if available) for violations.
 
For Splunk Enterprise (versions 8.1.0+), if you exceeded your license capacity 45+ times in a 60-day period with a stack volume <100 GB, search is disabled until violations clear or a reset license is applied.
 
If violations are still active (from before the new license), you may need to wait 30 days without violations (for free licenses) or request a reset license from Splunk Support (for Enterprise licenses).
 
Contact Splunk Support via the Splunk Support Portal or call 866.GET.SPLUNK to request a reset license. Apply it via Settings > Licensing > Add License.
 
Confirm Data Ingestion
 
  • Why: If logs aren’t appearing, the issue might not be the license but rather data not reaching the Search Head.
  • Action: Verify that data is being ingested and indexed.

index=* earliest=-24h

https://www.splunk.com/en_us/resources/splunk-enterprise-license-enforcement-faq.html 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @pacifiquen 

If there has been a period of time where the license wasnt valid and was not a non-enforcement license then it may be blocked. Does it give any warning about being over the licensed limit 5 times? What is the exact error?

Either way, it sounds likely that you will need a reset license code, this can be supplied by Splunk Support and/or your Splunk account manager/team and will need to be applied to your account in order to remove the limitation.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

PickleRick
SplunkTrust
SplunkTrust

Even a non-enforcement license blocks when it's past expiry date. Been there, done that 😉 On a multi-TB non-enforcement license. Someone missed the date and didn't upload the updated license in time, we had to call Splunk for the unlock license.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...