Simple question here:
ive been logging several logs recently. (often exceeding the 500mb cap) however, the indexing seems to have stopped for quite some time now.
ive added a new SINGLE log for testing stuff. up til now (since yesterday), the indexing has not occured. Could it be those old indexes are not done as when i started splunk this morning, there were some logs been indexed still but after a while the summary dashboards stopped updating, which i assumed = done. but my new file isnt there yet :(
Hope for some troubleshooting advice.
asked 31 May '12, 19:58
Sounds like you tripped the 500MB license limit one too many times. I assume you're either using the Enterprise trial, or the Free license? If so, you can only trip the license limit 5 times (Enterprise), or 3 times (Free) within a 30 day time period.
answered 31 May '12, 21:12
I would guess that you're out of space on one of the volumes on which Splunk runs or stores data. By default, Splunk will simply stop indexing when there is less then 2 GB of free space on any volume. You can adjust this threshhold using the
answered 31 May '12, 21:25