Alerting

Is this warning related to updating my license: 1 cle_pool_over_quota message reported by 1 Indexer?

KayBeesKnees83
Path Finder

Greetings, 

I recently uploaded my new term license. However, I noticed the following message:

* 1 cle_pool_over_quota message reported by 1 indexer - correct by midnight to avoid warning 

However, my company purchased a sizable term license. Is this message safe to ignore? I cannot provide a screenshot because I am operating on an airgapped network.

Furthermore, is there a way to mitigate this alert  to prevent receiving a warning? Again, we have a very large license and are quota is nowhere near our volume limit.

Is it somehow related to updating my license? As a I mentioned, I recently updated the new term license to replace the license that is set to expire. Or should I delete the pool from the previous license and create a new one associated with the new term license? 

Thank you. 

Labels (1)
0 Karma

codewire
Loves-to-Learn

I see you got no response to your question. Were you able to resolve the issue? And how did you go about it? I'm dealing with a similar situation. Thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...