My free license has expired. I have requested to extend and they extended the trail license. Below is the error I am facing when trying to search:
.Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.search results may be incomplete: the search process on the local peer:lsl30075 ended prematurely. Please check the local peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search
and in the splunkd.log, I can see the below errors
WARN IndexConfig - Max bucket size is larger than the index size limit. Please check your index configuration. idx=summary; bucket size in MB (from maxDataSize) 750, maxTotalDataSizeMB=5
and this errror/warn shows on all of my indexes.
How to get rid of these messages? Is there a way to delete the indexed data?
Urgent help needed.
What are license violations and warnings?
says -
-- Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days, or when you apply a temporary reset license (available for Enterprise only). To obtain a reset license, contact your sales rep. See the Installation Manual for instructions on how to apply it.
Free License Violation - How to Fix and Prevent Recurrence
says -
-- To regain search you need to go without violations for 30 days or ** just do a clean install ** and migrate your old configs and indexes over.
Hi murthy,
Once you violate your license searching will be blocked until a reset (only available to enterprise customers) is applied or you return to license compliance (30 days without exceeding the license limit). Only if you buy a larger license you will restore search functionality.
HI ,
I have reset to my licensing to my enterprise trail licence. I can seee all the alerts and reports but search is not functiong.
Check if the parameter maxDataSize < maxTotalDataSizeMB
in indexes.conf file. Here is more information about indexes.conf configuration.
http://docs.splunk.com/Documentation/Splunk/6.3.1/Admin/Indexesconf
If you want, post the lines of this parameters and we looking for errors or others.
This files is in SplunkHome/splunk/etc/system/local. Do not wiggle in this file when they is on .../default