Splunk® Enterprise

Installation Manual

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Install a license

This topic discusses how to install a new license in Splunk Enterprise. Before you proceed, you might want to review these topics on licensing:

Add a new license

To add a new license:

1. Navigate to Settings > Licensing.

2. Click Add license.

60 License add license.png

3. Either click Choose file and navigate to your license file and select it, or click copy & paste the license XML directly... and paste the text of your license file into the provided field.

4. Click Install. Splunk installs your license. If this is the first Enterprise license that you are installing, you must restart Splunk.

License violations

Violations occur when you exceed the maximum indexing volume allowed for your license. If you exceed your licensed daily volume on any one calendar day, you receive a violation warning. The message persists for 14 days. If you have 5 or more warnings on an Enterprise license or 3 warnings on a Free license in a rolling 30-day period, you are in violation of your license and Splunk disables search. Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days, or when you apply a temporary reset license (available for Enterprise only). To obtain a reset license, contact your sales rep.

Note: Summary indexing volume does not count against your license.

If you get a violation warning, you have until midnight (using the time on the license master) to resolve it before it counts against the total number of warnings within the rolling 30-day period.

During a license violation period:

  • Splunk never stops indexing your data. Splunk only blocks search while you exceed your license.
  • Splunk does not disable searches to the _internal index. This means that you can still access the Indexing Status dashboard or run searches against _internal to diagnose the licensing problem.

Got license violations? Read About license violations in the Admin Manual or Troubleshooting indexed data volume from the Splunk Community Wiki.

More licensing information is available in the "Manage Splunk licenses" chapter in the Admin Manual.

Last modified on 26 September, 2016
About Splunk Enterprise licenses
How to upgrade Splunk Enterprise

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters