Installation

Index Limit Reached

pmgsupport
New Member

I am a new user and just today created a new @indows 2008 R2 server and installed using the following script:

msiexec.exe /i splunk-6.0-182037-x64-release.msi AGREETOLICENSE=Yes INSTALLDIR="E:\Program Files\Splunk" WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 REGISTRYCHECK_LM=1 REGISTRYCHECK_BASELINE_LM=1 WMICHECK_CPUTIME=1 WMICHECK_LOCALDISK=1 WMICHECK_FREEDISK=1 WMICHECK_MEMORY=1 LOGON_USERNAME="DOM\DOMSPLUNK" LOGON_PASSWORD="asd34I2Wy" LAUNCHSPLUNK=1 INSTALL_SHORTCUT=1 /quiet

As soon as my install was successfully completed I logged into the web interface and noticed that my limit was reached due to the monitoring of my local event logs.

While I do not really have a good understanding of what the limit really means and how it effects my searches I would appreciate any advice. So far I have about 10 minutes of post install experience with the product.

Looks cool though.
-Ajay

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

Since this was a fresh Splunk install on machine that has been running for some time, I guess that the combined amount of all logs that you monitor exceed the 500MB/day limit that the 'Free' and 'Download Trial' licenses allow. So the first time Splunk starts up, it will consume all historical log entries for the specified log sources, and depending on your configuration for log file retention, that can be a lot.

Most likely, this will not be the case in the days to come, unless you have a very busy system. And you are allowed to have 3 license warnings within the last 30 days (rolling).

BTW, Welcome to Splunk! Hope you enjoy the ride.

/K

lukejadamec
Super Champion

In Splunk/etc/apps/MSICreated/local you should find an inputs.conf file that will contain the configuration for monitoring your local event logs. Change disable from 0 to 1 for the events you don't want, and restart Splunk.

0 Karma

pmgsupport
New Member

Thank you Kristian for your quick response. I will limit my inputs and hope that the indexer is good to me.

Is there a method for me to remove the data collected from the local event log? The local machine (splunk server) event log data is not of interest to me.
-Ajay

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...