Splunk Search

Search does not work and also stopped indexing data.

hylee
Explorer

Search does not work with this message.

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

So, I changed to Free License From Trial License.
But, Search still does not work and also stopped indexing data.

License information is Below (Settings > Licensing)

Current
No licensing alerts
Permanent
8 license window warnings reported by 1 indexer  1 week ago

Local server information

Indexer name    WIN-V7LE2D5OJ6G
License expiration   Feb 9, 2014 1:18:11 PM
Licensed daily volume    500 MB
Volume used today    0 MB (0% of quota)
Warning count   8
Debug information   All license details 
All indexer details.

How do I use normally as before? What should I do?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

With eight warnings in your license window, neither Splunk Free nor Splunk Trial nor Splunk Enterprise will let you search.

You can either wait for sufficient warnings to disappear from your 30-day window, or get a warning reset key from Splunk. As a Splunk Free user the latter probably is not an option though.

martin_mueller
SplunkTrust
SplunkTrust

Provided you don't add new warnings by indexing more than your daily license volume, yes.

Every warning will move out of the window after 30 days, so it should take no more than that to get below 5 warnings (3 for Splunk Free).

See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations for more info.

0 Karma

hylee
Explorer

Thanks for your answer. So, Do I need to just wait for a month? After 1 month, this problem will be disappeared?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...