Install a license
This topic discusses installing new licenses. Before you proceed, you may want to review these topics:
- Read "How Splunk licensing works" in the Admin Manual for an introduction to Splunk licensing.
- Read "Groups, stacks, pools, and other terminology" in the Admin Manual for more information about Splunk license terms.
Add a new license
To add a new license:
1. Navigate to Manager > Licensing.
2. Click Add license.
3. Either click Choose file and navigate to your license file and select it, or click copy & paste the license XML directly... and paste the text of your license file into the provided field.
4. Click Install. If this is the first Enterprise license that you are installing, you must restart Splunk. Your license is installed.
Violations occur when you exceed the maximum indexing volume allowed for your license. If you exceed your licensed daily volume on any one calendar day, you will get a violation warning. The message persists for 14 days. If you have 5 or more warnings on an Enterprise license or 3 warnings on a Free license in a rolling 30-day period, you are in violation of your license and search will be disabled. Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days, or when you apply a temporary reset license (available for Enterprise only). To obtain a reset license, contact your sales rep.
Note: Summary indexing volume is not counted against your license.
If you get a violation warning, you have until midnight (going by the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period.
During a license violation period:
- Splunk does not stop indexing your data. Splunk only blocks search while you exceed your license.
- Searches to the
_internalindex are not disabled. This means that you can still access the Indexing Status dashboard or run searches against
_internalto diagnose the licensing problem.
More licensing information is available in the "Manage Splunk licenses" chapter in the Admin Manual.
About Splunk Enterprise licenses
How to upgrade Splunk
This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18