Getting Data In

Data indexing through the period of license violation

SRIVATSAN_IYER
Explorer

Approximately, 10 days back Splunk raised License Violation because of exceeding the quota multiple times. We have now acquired a reset license and applied it a few hours back. Things seem to be back to normal.

My question is:

Although we can see events from the past one week on Splunk, a confirmation that Splunk was continuously indexing the data throughout the period of license violation (but just not allowing the search) would be very helpful. What we would like to avoid is that the indexed data is left in an inconsistent state because of this issue. Can somebody confirm this?

Any answers for this would be highly appreciated. Thanks!

Jeff_Lightly_Sp
Communicator

Data should still have been indexed...

From the manual located at: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

During a license violation period:

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
Searches to the _internal index are not disabled. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...