Getting Data In

Why am I unable to view logs after a Splunk restart?

mohinder6
New Member

So I recently hit the threshold error message. It said something like "Disk space 5000MB reached. Indexing paused". I did a temporary fix by lowering the threshold value to 200MB and it asked for a Splunk restart. I restarted Splunk through the GUI and I no longer see the threshold error while searching.
However, it's been like 30 mins now and I'm still not able to view the latest logs. Is it supposed to take some significant amount of time? If not what is the issue?

0 Karma

MuS
Legend

Hi mohinder6,

like @Sarmbrister said, you ran into a license violation and your search will stop after 3 violation in a rolling window of 30 days. Your search will resume after 30 days, read the docs http://docs.splunk.com/Documentation/Splunk/6.2.6/Admin/Aboutlicenseviolations to learn more about license violations.

Also, you're using Splunk free and I think it is still not possible or at least, very hard to get a reset key for Splunk free. So read this comment to learn about one method to reset Splunk free http://answers.splunk.com/answers/66786/free-license-reset.html#comment-66791

Hope this helps ...

cheers, MuS

Sarmbrister
Path Finder

is this the 5th time this month you have received this message? If so splunk doesn't stop indexing the data it just doesnt allow you to search any more for that day.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...