I've been banging my head against the wall (and Splunk) trying to figure out how I possibly could be exceeding my license with logging 4 systems. Twas fun to troubleshoot since I cannot do query License Usage or do a License Report because Search disabled. Fun. Anyway...
I saw this post while going through the forum working on this problem and I have the same exact issue. Thanks for posting this. I never would have thought that Splunk would have flip my license over to something that was going to simply auto-violate repeatedly until locked out for 30 days (actually 30 days from the date you catch it).
I think I saw a few posts where folks were having licensing issues and it's probably exactly this.
Needless to say, I am interested in the solution as well.
I've seen mention of a License Reset. Which I am going to look into more now.
thanks,
Ted
... View more