Security

Indexing Quota with Free License

cvajs
Contributor

v4.3.1 on sles 11.1

just finished a enterprise eval so when i logged in today i got some over quota messages. i made sure in Manager > Licensing that it is now Free lic model.

my daily indexing volume is ~150MB, so why these warning messages? it has thus disabled searching per the Free model, why?

Correct by midnight to avoid violation Learn more   This pool contains slave(s) with 4 warnings     myHost  auto_generated_pool_free    free    pool_warning_count

Apr 16, 2012 12:00:00 AM
(11 hours ago)  Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 15, 2012 12:00:00 AM
(1 day ago)     Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 14, 2012 12:00:00 AM
(2 days ago)    Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
    Apr 13, 2012 12:00:00 AM
(3 days ago)    Indexing quota exceeded for this pool, poolsz=0 bytes   myHost  auto_generated_pool_enterprise  enterprise  license_window
Tags (3)
0 Karma

kaililleby
New Member

Did you ever find a solution other than waiting for 30 days?

0 Karma

Drainy
Champion

Well according to the log messages you have exceeded the indexing volume three times (which means a 30 day search shutdown).

To overcome this you will either have to wait 30 days for search to return or perhaps do a clean install and migrate over your data.

0 Karma

cvajs
Contributor

well, according the the stats for _internal index my daily indexing doesnt surpass 160MB. and, how could i exceed the quota if i had 50GB trial lic installed and then went to free, these messages came instantly right after the trial lic expired and i switched to free.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...