Hello,
I had an issue with one of our applications which generate too many events => I have been in 5 days of license violation.
Searches are disabled as I am in a pre 6.5 Splunk Enterprise license mode.
I fixed the issue with the application so my daily volume of event is back to beeing bellow my license Gb/Day:
- Do I have to way for 26 days ( so that the number of violations over the last 30 days goes down to less than 5 #) or is there another way of recovering access to the searchs/requests/dashboards ?
- Will the service be available tomorrow again ?
- Is it possible to "reset" the count ?
Thank you
↧