Approximately, 10 days back Splunk raised License Violation because of exceeding the quota multiple times. We have now acquired a reset license and applied it a few hours back. Things seem to be back to normal.
My question is:
Although we can see events from the past one week on Splunk, a confirmation that Splunk was continuously indexing the data throughout the period of license violation (but just not allowing the search) would be very helpful. What we would like to avoid is that the indexed data is left in an inconsistent state because of this issue. Can somebody confirm this?
Any answers for this would be highly appreciated. Thanks!
Data should still have been indexed...
From the manual located at: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations
During a license violation period:
Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
Searches to the _internal index are not disabled. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.