Is it posible to downgrade from Splunk enterprise to Splunk free version? We are currently using the Splunk Enterprose version, and would like to downgrade to free version of splunk. How we can operate this downgrade withput loosing any log data?
Sure it is possible, you can change license to "Free license" under Licensing menu in Settings tab and stored data will not be lost (such easy way only for all in one installations!).
But you will face limitations of free license like access control, usage of distributed environment, daily data volume and etc.
You can read here more about Splunk licenses and limitations of free license
Hi, could you please elaborate on "such easy way only for all in one installations"?
If I have an indexer cluster with 3 indexers, and one search head, is there any special procedure that needs to be performed to ensure the indexers will preserve the already existing data?