Dashboards & Visualizations

Does enabling Splunk Free force all incoming data into a particular index?

malmoore
Splunk Employee
Splunk Employee

I'm thinking about switching my Splunk server from the enterprise trial to Splunk Free. Right now I've got data being sent to several indexes. Will enabling Splunk Free force data to be sent to a specific index (for example, the default index 'main') or will data continue to flow into the indexes I've already defined, as long as I don't hit my daily indexing limit?

0 Karma

e82than
Communicator

Yeah, romantercero is right. It does not care how many index you have. It is only concerned about the volume of data that is going into splunk indexer.

0 Karma

romantercero
Path Finder

The free version of Splunk comes with various indexes out of the box and the documentation does not mention any limits on the number of indexes you create or where the information gets sent to. I've actually created some myself on the free version.

This might help:

http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree

Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...