Well, I guess it was observation / feedback, more than a specific question. However, some questions come to mind:
Why is Splunk implemented such an draconian license enforcement system on an evaluation version?
Since this is enforced in the eval. version, why is this limitation not made more obvious in the initial documentation (possibly even stating it in the emails from the sales rep)?
Why isn't this mentioned on every admin login, even after just one warning? I don't remember reading about the search function eventually being disabled with any of the warnings, or in the messages menu, or upon logging in; I think I would have noticed at least in same cases, but maybe I missed all of them
Why, after the search block occurs, the only obvious error message that you get upon searches returning zero items is "Peer SPLUNK's search ended prematurely. Attempting to reconnect and resume"? Would a banner such as "The search function has been disabled due to excessive number of traffic warnings, see this URL in the documentation for info" be too on the nose?
Thanks,
Luca
... View more