Installation

Index Limit Reached

pmgsupport
New Member

I am a new user and just today created a new @indows 2008 R2 server and installed using the following script:

msiexec.exe /i splunk-6.0-182037-x64-release.msi AGREETOLICENSE=Yes INSTALLDIR="E:\Program Files\Splunk" WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 REGISTRYCHECK_LM=1 REGISTRYCHECK_BASELINE_LM=1 WMICHECK_CPUTIME=1 WMICHECK_LOCALDISK=1 WMICHECK_FREEDISK=1 WMICHECK_MEMORY=1 LOGON_USERNAME="DOM\DOMSPLUNK" LOGON_PASSWORD="asd34I2Wy" LAUNCHSPLUNK=1 INSTALL_SHORTCUT=1 /quiet

As soon as my install was successfully completed I logged into the web interface and noticed that my limit was reached due to the monitoring of my local event logs.

While I do not really have a good understanding of what the limit really means and how it effects my searches I would appreciate any advice. So far I have about 10 minutes of post install experience with the product.

Looks cool though.
-Ajay

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

Since this was a fresh Splunk install on machine that has been running for some time, I guess that the combined amount of all logs that you monitor exceed the 500MB/day limit that the 'Free' and 'Download Trial' licenses allow. So the first time Splunk starts up, it will consume all historical log entries for the specified log sources, and depending on your configuration for log file retention, that can be a lot.

Most likely, this will not be the case in the days to come, unless you have a very busy system. And you are allowed to have 3 license warnings within the last 30 days (rolling).

BTW, Welcome to Splunk! Hope you enjoy the ride.

/K

lukejadamec
Super Champion

In Splunk/etc/apps/MSICreated/local you should find an inputs.conf file that will contain the configuration for monitoring your local event logs. Change disable from 0 to 1 for the events you don't want, and restart Splunk.

0 Karma

pmgsupport
New Member

Thank you Kristian for your quick response. I will limit my inputs and hope that the indexer is good to me.

Is there a method for me to remove the data collected from the local event log? The local machine (splunk server) event log data is not of interest to me.
-Ajay

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...