Splunk Search

Search does not work and also stopped indexing data.

hylee
Explorer

Search does not work with this message.

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

So, I changed to Free License From Trial License.
But, Search still does not work and also stopped indexing data.

License information is Below (Settings > Licensing)

Current
No licensing alerts
Permanent
8 license window warnings reported by 1 indexer  1 week ago

Local server information

Indexer name    WIN-V7LE2D5OJ6G
License expiration   Feb 9, 2014 1:18:11 PM
Licensed daily volume    500 MB
Volume used today    0 MB (0% of quota)
Warning count   8
Debug information   All license details 
All indexer details.

How do I use normally as before? What should I do?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

martin_mueller
SplunkTrust
SplunkTrust

Provided you don't add new warnings by indexing more than your daily license volume, yes.

Every warning will move out of the window after 30 days, so it should take no more than that to get below 5 warnings (3 for Splunk Free).

See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations for more info.

0 Karma

hylee
Explorer

Thanks for your answer. So, Do I need to just wait for a month? After 1 month, this problem will be disappeared?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...