Getting Data In

Data indexing through the period of license violation

SRIVATSAN_IYER
Explorer

Approximately, 10 days back Splunk raised License Violation because of exceeding the quota multiple times. We have now acquired a reset license and applied it a few hours back. Things seem to be back to normal.

My question is:

Although we can see events from the past one week on Splunk, a confirmation that Splunk was continuously indexing the data throughout the period of license violation (but just not allowing the search) would be very helpful. What we would like to avoid is that the indexed data is left in an inconsistent state because of this issue. Can somebody confirm this?

Any answers for this would be highly appreciated. Thanks!

Jeff_Lightly_Sp
Communicator

Data should still have been indexed...

From the manual located at: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

During a license violation period:

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
Searches to the _internal index are not disabled. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...