Installation

How to resolve Splunk License usage alert?

sunnyparmar
Communicator

Hi,

Can anyone tell me how to resolve a Splunk License alert problem? I have fixed the alarm at 90% so once it will reach 90% how can I solve this issue? In my graph it is showing by host, sourcetype, source, and index that which one is consuming more license? So after seeing the result how to solve this issue?

Thanks
Ankit

Labels (1)
0 Karma

drumster88
Explorer

To ensure that you don't get any license violations, monitor your license usage and make sure your license volume is sufficient to support your operational usage. If you do not have sufficient license volume you need to either increase your license or can also go for tweaking your indexing volume.

jensonthottian
Contributor

Yes. If you are using Splunk 6.0, you must have set up alert for any of the searches in the License Usage Report View. See Use the License Usage Report View in the Admin Manual. If you are using Splunk 5.x, install the Splunk on Splunk app and you will have access to the same views for your Splunk 5.x installation.

Check the $SPLUNK_HOME/var/log/splunk/license_usage.log, to check which index is more license. How to resolve the issue is check the license usage, get it increased if you are continuously reaching 90% limit.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...