My free license has expired. I have requested to extend and they extended the trail license. Below is the error I am facing when trying to search:
.Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.search results may be incomplete: the search process on the local peer:lsl30075 ended prematurely. Please check the local peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search
and in the splunkd.log, I can see the below errors
WARN IndexConfig - Max bucket size is larger than the index size limit. Please check your index configuration. idx=summary; bucket size in MB (from maxDataSize) 750, maxTotalDataSizeMB=5
and this errror/warn shows on all of my indexes.
How to get rid of these messages? Is there a way to delete the indexed data?
Urgent help needed.
Once you violate your license searching will be blocked until a reset (only available to enterprise customers) is applied or you return to license compliance (30 days without exceeding the license limit). Only if you buy a larger license you will restore search functionality.
I have reset to my licensing to my enterprise trail licence. I can seee all the alerts and reports but search is not functiong.
Check if the parameter
maxDataSize < maxTotalDataSizeMB in indexes.conf file. Here is more information about indexes.conf configuration.
If you want, post the lines of this parameters and we looking for errors or others.
This files is in SplunkHome/splunk/etc/system/local. Do not wiggle in this file when they is on .../default
-- Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days, or when you apply a temporary reset license (available for Enterprise only). To obtain a reset license, contact your sales rep. See the Installation Manual for instructions on how to apply it.
-- To regain search you need to go without violations for 30 days or ** just do a clean install ** and migrate your old configs and indexes over.