Refine your search:

I am still on a trial of the enterprise version. I have one central splunk server and several forwarders setup.

This morning Splunk says: Daily indexing volume limit exceeded.

Can I back track and remove something?

I have one file that was added directly as a input to splunk that generated a lot of traffic. I tried sourcetype=<> | delete but it seems to struggle deleting >20M events.

Is it something I'm doing wrong?

Can I setup Splunk to prune indexed data older than X and I just missed that setting somewhere?

Thanks.

asked 03 Dec '10, 15:22

charlesg's gravatar image

charlesg
111
accept rate: 0%

edited 04 Oct '11, 02:27

jlaw's gravatar image

jlaw ♦
74148


One Answer:

Unfortunately there is no way to reverse/unindex data that caused you to violate the license. Search should still work, as should indexing -- you can violate the license a few times in any given 30 day period and still have a working system.

Even if you adjust retention times, this will not affect your indexing license. The licensing model is based on daily index volume, not total indexed volume over all time.

link

answered 03 Dec '10, 15:28

ftk's gravatar image

ftk ♦
6.8k1727
accept rate: 38%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×468
×100
×85
×70

Asked: 03 Dec '10, 15:22

Seen: 2,135 times

Last updated: 04 Oct '11, 02:27

Copyright © 2005-2012 Splunk Inc. All rights reserved.