Archive

Splunk unable to search auth.log after free trial expired?

Path Finder

Hi,

My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?

0 Karma
1 Solution

Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

Champion

What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.

0 Karma

SplunkTrust
SplunkTrust

Hey

Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances

3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.

Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree

Let me know if this helps you!

0 Karma

Path Finder

Hi,

I'm none of the above. No violations for the past 30 days.

0 Karma

SplunkTrust
SplunkTrust

are you getting messages like "you have exceeded your license limit too many times"?

0 Karma

Path Finder

nope. Only new version available message.

0 Karma

SplunkTrust
SplunkTrust

check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license

0 Karma