Installation

How do I get the correct volume showing for our licensing?

gillisme
New Member

Environment - single splunk enterprise instance (v. 8.2.6) running on a RHEL 6.1 server, receiving data from  multiple forwarders.

Issue - License volume has always shown as 30GB/day, for the past few years anyway. Found out today that the last license purchased (January 2022) was for 50GB/Day, but the license page is still showing 30G/day.

gillisme_0-1673882544945.png

How do I get the correct volume showing for our licensing? I would have thought it would have been automatic, or part of the license install process.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

To be fully honest with you, it's an unusual situation. Firstly, non-enforcement licenses don't come up that small typically. And secondly - license up until 2038? (effectively not time-limited one)

 

0 Karma

gillisme
New Member

Yes, that end date was unexpected but I figured it was some sort of 'grace' period while licensing was worked out? Seems a little excessive, but we are a government entity, I am sure Splunk is confident they will be getting fully paid in the end.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can check the license files in /opt/splunk/etc/license/enterprise. There you should find xml files (digitally signed so don't fiddle with them ;-)) with expiration_time (as unix timestamp) and quota.

If they agree with what your bought license terms, try restarting your splunk instance. Maybe for some reason the latest changes didn't "catch up". If they don't - it seems more like an issue for your Account Manager.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps the latest license was not installed.  Have your Portal Admin sign in to the Support Portal and download the latest license.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gillisme
New Member

OK, thanks, will try that. I guess I am the portal admin, the guy who set this up is long gone, I am keeping the lights on while trying to migrate to newer splunk version on newer RHEL vm. Steep learning curve.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...