Splunk Search

Search blocked by license notice

scarpio
Explorer

Hello,

We recently installed Splunk, we thought we had a free license, however we got a notice that we have exceeded the quota and the license has been blocked. We have changed the license group to free, however the search is still blocked.

How can we unlock it?

Thank you very much and greetings!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

View solution in original post

scarpio
Explorer

Hello,

For the unlock code can I request if you are not a splunk customer? That is, you only have the Free version.

In case you have to reinstall, what folder do you mean by %SPLUNK_DB ?

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

the $SPLUNK_DB is the folder where the splunk indexes are stored, you can find it in $SPLKUNK_HOME/etc/splunk-launch.conf or in [Settings -- Server Settings -- General Settings].

By default it's $SPLUNK_HOME/var/lib/splunk.

If you aren't a Splòunk customer I'm not sure that you can requeste an unblock code, if you're a Splunk Partner you can ask it.

Ciao.

Giuseppe

scarpio
Explorer

Hello,

Investigating I have seen that the block is removed if there are no alerts in the licenses in the last 30 days.

Is this true? If we wait a month and the alerts pass for the previous license, it would be unlocked.

Thank you very much and greetings!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @scarpio,

using the Trial or the Free License, there's the block if you have three exceedings in the last 30 solar days.

I'm not sure that the block will be removed after 30 days because I always needed to remove the problem using an unblock code, but I don't think it's true.

I hint to follow the other hints.

Let me know if this answer solves your need, and eventually please accept it for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ ,

when a license is blocked for exceeding you have to insert an unblock code, that you can have from Splunk Channel Manager or from you Splunk Partner.

Otherwise, if you're using Linux, you could uninstall Splunk and reinstall it.

Doing this, you can save your configurations and data backupping the SPLUNK_HOME/etc folder and %SPLUNK_DB folder, and then copy them in the new installation.

But anyway beware becuase with the Trial or the Free license, you can only index 500 MB/day and you have only three exceedings.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...