Hi
I'm running a trial of Splunk 4.2.4 on our webserver - just one installation, with no forwarders and not pulling any data from separate machines.
I had a problem with my log files yesterday, and resolved it by adding crcSalt=<SOURCE> to my IIS logfile data inputs - unfortunately I forgot to remove the already-indexed logs, so duplicated a lot of data and exceeded my license amount.
Today I'm getting a second license alert, with the warning This pool contains slave(s) with 1 warnings . I can't think what this could be referring to, and I'm not sure how to check. I know that if I hit the warning again tomorrow, I'll potentially lose search for 30 days.
Any/all help much appreciated!
Thanks, Adam
Update
I've installed the deployment monitor app, and backfilled the data - it's reporting 0 forwarders, 1 indexer and 1 license pool.
I've just noticed that if I log into splunk.com, my account is listed as having no evaluation licenses. Could that be it? I only installed the trial copy 3 days ago and it should be good for 60 days on the trial.
... View more