Installation

One index exceeded the Splunk daily license limit and is displaying the message "Correct by midnight to avoid violation". How do I remove this warning?

pavanae
Builder

We are using a standalone environment and one of the indexes has exceeded the daily license volume (50 GB) and indexed around 82 GB which had caused the warning 2 weeks with the message "Correct by midnight to avoid violation". Since then, I have been seeing the warning everyday, the index which exceeded the daily license volume has not been properly indexing the data, and I'm missing lots of events while I am searching.

Our Environment - Stand Alone
License version - 6.1.3
No of pools - 1
License purchased - 50 GB /day
License violation - 1 day (indexed 86 GB with license of 50 GB)

How do I get rid of this warning, and are missing events from some of the hosts in that index actually due to the license violation?

Please suggest what to do.

Sorry for the grammar and Thanks in Advance.

Labels (1)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Have you reviewed the documentation here? If you are an enterprise customer (which it sounds like you are), you get 5 daily licensed indexing volume violation in a rolling 30 day period.
Splunk does not ever suspend indexing as a result of a license violation. If you reach 5 violations in a 30-day period, search will be disabled, but indexing will continue.
You will only need a reset key if you maxed out your violations, i.e. if you do not ensure that you stay within your licensed daily limit.

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee

Have you reviewed the documentation here? If you are an enterprise customer (which it sounds like you are), you get 5 daily licensed indexing volume violation in a rolling 30 day period.
Splunk does not ever suspend indexing as a result of a license violation. If you reach 5 violations in a 30-day period, search will be disabled, but indexing will continue.
You will only need a reset key if you maxed out your violations, i.e. if you do not ensure that you stay within your licensed daily limit.

bmacias84
Champion

Contact Support for a license reset key. Make sure you are not continually exceeding you daily license limit. You are allowed 3 violation per month.

0 Karma

pavanae
Builder

I have exceeded only 1 time this month. So contacting support for reset key is the only option or is there anyway i can resolve the situation?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...