Splunk Search

Ran with expired trial for a few days. Do I have to wait 30 days for search to work?

rpeters_tlm
New Member

We were using the download-trial license. It expired but we didn't notice for two weeks, so we exceeded for each of those days.

Now that we have converted to the free license, do we have to wait for 30 more days for the exceeded days to roll out?

Tags (1)
0 Karma

rpeters_tlm
New Member

Thanks Duker. I have submitted a ticket.

0 Karma

theduker
New Member

I opened a ticket yesterday and received a Splunk Reset License via email from Support. Instructions are included and easy to follow.

The one thing that they don't tell you to do is after you apply this reset license you then need to go and revert back to your previous license. Manager » Licensing » Change license group -> select Free license.

The license sent to me was a 1MB enterprise license, which (of course) immediately was in violation. Though I could search and view info again. Once I change back to the Free License, the violations all went away and I am in business again.

Hope that helps.

Ted

0 Karma

theduker
New Member

I've been banging my head against the wall (and Splunk) trying to figure out how I possibly could be exceeding my license with logging 4 systems. Twas fun to troubleshoot since I cannot do query License Usage or do a License Report because Search disabled. Fun. Anyway...

I saw this post while going through the forum working on this problem and I have the same exact issue. Thanks for posting this. I never would have thought that Splunk would have flip my license over to something that was going to simply auto-violate repeatedly until locked out for 30 days (actually 30 days from the date you catch it).

I think I saw a few posts where folks were having licensing issues and it's probably exactly this.

Needless to say, I am interested in the solution as well.

I've seen mention of a License Reset. Which I am going to look into more now.

thanks,

Ted

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...