It seems like every other day I attempt to use Splunk and I get the following:
"503 Service Unavailable
Return to Splunk home page
The splunkd daemon cannot be reached by splunkweb. Check that there are no blocked network ports or that splunkd is still running."
I then restart splunkd and I can get back in. I'm pretty new to splunk, so I'm unsure how to troubleshoot this. Is there a log that will help me diagnose this issue? I noticed in the license_audit.log it says the following:
"10-11-2012 00:00:01.015 INFO LicenseManager-Audit - Audit:[quotaExceededCount=0, lastExceedDate=1331794800, peak=213689346, rolloverCount=3, totalCumulativeBytesAtRollover=213689346, todaysBytesIndexed=213689346, licenseSize=524288000][C2e5bdtQOCkMHQNZsE3EhmfY7l5E/F7K7liuBjCy8xR708UOgo1jK3zZxhQsgKDzLV/+eyDh1sfGuWRIhjUqrKouiRVK6YtLX1PosMy4W9L6vankNm60b4pV4YB3hcZ8wD2WPmpm17hxCWqfCKB+rKTSq1XjuFBa7XNpdUHeE1eeEikdIMOeh8obqf1Im//Jajxi6zZ+4OF44Vj29h6PwrMULwVMbE2X3Hgh+w/+nPjxbp1mAPlOsrNIvKG7iCJV30zyiPA4VT2HarE8MdDG546WWkrVGx36hgsPy3WapBp8elLdwiqGFVMxGFTngQOgUBWB7VYHWtxphN/nUE2Lzg==]"
Could this be a simple case of just processing too many logs for my given license?
Running on Ubuntu 10.04 with Splunk 4.3 build 115073, using the free license.
Any help would be greatly appreciated.
AG
aarong@smartshoot.com
... View more