Splunk Search

Search blocked by license notice

scarpio
Explorer

Hello,

We recently installed Splunk, we thought we had a free license, however we got a notice that we have exceeded the quota and the license has been blocked. We have changed the license group to free, however the search is still blocked.

How can we unlock it?

Thank you very much and greetings!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

View solution in original post

scarpio
Explorer

Hello,

For the unlock code can I request if you are not a splunk customer? That is, you only have the Free version.

In case you have to reinstall, what folder do you mean by %SPLUNK_DB ?

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

scarpio
Explorer

Hello,

Investigating I have seen that the block is removed if there are no alerts in the licenses in the last 30 days.

Is this true? If we wait a month and the alerts pass for the previous license, it would be unlocked.

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @scarpio,

using the Trial or the Free License, there's the block if you have three exceedings in the last 30 solar days.

I'm not sure that the block will be removed after 30 days because I always needed to remove the problem using an unblock code, but I don't think it's true.

I hint to follow the other hints.

Let me know if this answer solves your need, and eventually please accept it for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

when a license is blocked for exceeding you have to insert an unblock code, that you can have from Splunk Channel Manager or from you Splunk Partner.

Otherwise, if you're using Linux, you could uninstall Splunk and reinstall it.

Doing this, you can save your configurations and data backupping the SPLUNK_HOME/etc folder and %SPLUNK_DB folder, and then copy them in the new installation.

But anyway beware becuase with the Trial or the Free license, you can only index 500 MB/day and you have only three exceedings.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...