Splunk Search

Search does not work and also stopped indexing data.

hylee
Explorer

Search does not work with this message.

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

So, I changed to Free License From Trial License.
But, Search still does not work and also stopped indexing data.

License information is Below (Settings > Licensing)

Current
No licensing alerts
Permanent
8 license window warnings reported by 1 indexer  1 week ago

Local server information

Indexer name    WIN-V7LE2D5OJ6G
License expiration   Feb 9, 2014 1:18:11 PM
Licensed daily volume    500 MB
Volume used today    0 MB (0% of quota)
Warning count   8
Debug information   All license details 
All indexer details.

How do I use normally as before? What should I do?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

martin_mueller
SplunkTrust
SplunkTrust

Provided you don't add new warnings by indexing more than your daily license volume, yes.

Every warning will move out of the window after 30 days, so it should take no more than that to get below 5 warnings (3 for Splunk Free).

See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations for more info.

0 Karma

hylee
Explorer

Thanks for your answer. So, Do I need to just wait for a month? After 1 month, this problem will be disappeared?

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...