Splunk Enterprise

Why does Splunk Licensing Warnings pop up when adding sources after installing Splunk Enterprise on Ubuntu 20.04?

jonare
Engager

Hello

I have installed Splunk Enterprise on Ubuntu 20.04 two times now, but I get warnings from licensing when adding sources.

I installed a 5GB/days license and added a syslog udp/1514 and a new index. After this splunk starts complaining about:

 

This deployment is subject to license enforcement. Search is disabled after 45 warnings over a 60-day window Learn more

Licensing alerts notify you of excessive indexing warnings and licensing misconfigurations

 

 

1 cle_pool_over_quota message reported by 1 indexer	Correct by midnight to avoid warning

 

Can anyone help me in the right direction ? The total amout of data = 0MB, so this is clearly not correct.

Regards, Jon

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...