Splunk Enterprise

Why am I receiving this Licensing Issue?

cpm003
Path Finder

Hi there,

I´m getting following advice on licensing page:

"This deployment is subject to license enforcement. Search is disabled after 45 warnings over a 60-day window"

I don't know what it´s are referring to.

 

Labels (3)
0 Karma

Stefanie
Builder

It's saying you're ingesting more data than your license allows you to. 

From Splunk:

If you exceed license capacity 45 or more times in a rolling 60-day period and have a license stack volume less than 100 GB on Splunk Enterprise version 8.1.0 and above, the software will disable your search functionality. In cases where license pools have strict quota enabled, search is disabled for the offending license pool member(s) after 45 warnings over a rolling 60-day window for the license pool.

 

 

0 Karma

cpm003
Path Finder

I don´t know what´s happening

cpm003_0-1649334604147.png

 

0 Karma

Stefanie
Builder

On the page you took that screenshot there should be a "Usage Report" button. This will take you to a set of dashboards that will let you look at how much you've ingested over time. On one or more days within the last 30-60 days you ingested more than 1024 MB of data. 

You have a "No enforcement" License meaning after 30 days your searches will not be disabled but if you are constantly having this error message it might be time to look at increasing your license. 

0 Karma

cpm003
Path Finder

i recently migrated indexes from a pre-production enviroment, this might be related to

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...