Getting Data In

Data indexing through the period of license violation

SRIVATSAN_IYER
Explorer

Approximately, 10 days back Splunk raised License Violation because of exceeding the quota multiple times. We have now acquired a reset license and applied it a few hours back. Things seem to be back to normal.

My question is:

Although we can see events from the past one week on Splunk, a confirmation that Splunk was continuously indexing the data throughout the period of license violation (but just not allowing the search) would be very helpful. What we would like to avoid is that the indexed data is left in an inconsistent state because of this issue. Can somebody confirm this?

Any answers for this would be highly appreciated. Thanks!

Jeff_Lightly_Sp
Communicator

Data should still have been indexed...

From the manual located at: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

During a license violation period:

Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
Searches to the _internal index are not disabled. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...