Splunk Search

Search blocked by license notice

scarpio
Explorer

Hello,

We recently installed Splunk, we thought we had a free license, however we got a notice that we have exceeded the quota and the license has been blocked. We have changed the license group to free, however the search is still blocked.

How can we unlock it?

Thank you very much and greetings!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

View solution in original post

scarpio
Explorer

Hello,

For the unlock code can I request if you are not a splunk customer? That is, you only have the Free version.

In case you have to reinstall, what folder do you mean by %SPLUNK_DB ?

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

scarpio
Explorer

Hello,

Investigating I have seen that the block is removed if there are no alerts in the licenses in the last 30 days.

Is this true? If we wait a month and the alerts pass for the previous license, it would be unlocked.

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @scarpio,

using the Trial or the Free License, there's the block if you have three exceedings in the last 30 solar days.

I'm not sure that the block will be removed after 30 days because I always needed to remove the problem using an unblock code, but I don't think it's true.

I hint to follow the other hints.

Let me know if this answer solves your need, and eventually please accept it for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

when a license is blocked for exceeding you have to insert an unblock code, that you can have from Splunk Channel Manager or from you Splunk Partner.

Otherwise, if you're using Linux, you could uninstall Splunk and reinstall it.

Doing this, you can save your configurations and data backupping the SPLUNK_HOME/etc folder and %SPLUNK_DB folder, and then copy them in the new installation.

But anyway beware becuase with the Trial or the Free license, you can only index 500 MB/day and you have only three exceedings.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...