Installation

license violation despite "no-enforcement" license

frank_buettner
Explorer

We are using Splunk 6.5.0 and we have a "no-enforcement" license. Despite that, the search stops working[2] after a violation. Are we making something wrong or do we have a different interpretation of "search is not blocked"[1]?

I would like to provide some screenshots, but I'm missing some karma points...

[1]
http://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/TypesofSplunklicenses

[2]
"Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK."

Tags (1)
0 Karma
1 Solution

frank_buettner
Explorer

In the meantime we got a license with the name "Splunk Enterprise Reset Warnings" form out distributor. This one resets all warnings. So contacting the Splunk support respectively the distributor helps.

This special license has an expiration date. After the expiration we are still able to search.

View solution in original post

dkolekar_splunk
Splunk Employee
Splunk Employee

No-enforcement license
If your license master is running Splunk Enterprise 6.5.0 or later, you can use a no-enforcement Enterprise license. This new license type allows users to keep searching even if you acquire five warnings in a 30-day window. Your license master still considers itself in violation, but the search is not blocked.

A no-enforcement license stacks with other Enterprise licenses. Stacking a no-enforcement license on top of another valid Enterprise license changes the behavior of the entire stack to the no-enforcement behavior.

If you violate the purchased license limit, you need to contact Splunk support in order to get the reset key. After applying the reset key, error messages will go away.

What is my legal obligation if I exceed my purchased license capacity?
Your legal obligations remain unchanged. Splunk's EULA language specifically states that customers cannot exceed their Licensed Capacity. If you do, you need to purchase additional capacity to remain in compliance with your license. The relevant sections of the EULA (https://www.splunk.com/en_us/legal/splunk-software-license-agreement.html) are listed below:
Section 3: LICENSE RESTRICTIONS states that customers cannot exceed their purchased license capacity
Section 9: SOFTWARE VERIFICATION AND AUDIT spells out Splunk's right to verify and/or audit the customer's usage of Splunk software

Is there any limit to license reset keys from Splunk?
3 per 3 months, per account/company

0 Karma

frank_buettner
Explorer

In the meantime we got a license with the name "Splunk Enterprise Reset Warnings" form out distributor. This one resets all warnings. So contacting the Splunk support respectively the distributor helps.

This special license has an expiration date. After the expiration we are still able to search.

deepashri_123
Motivator

Hey@frank_buettner,

You need to contact Splunk support for this scenario.
Let me know if this helps!!

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...