Deployment Architecture

Splunk free - setting up a distributed environement (Search Head, 1 IDX, 1 UF, maybe a deployment server)

spluzer
Communicator

Hey Splunksters,

My work environment is switching from Windows (large distributed enviro) to Linux pretty soon.

I'd like to get familiar with architecting in Linux so I had a couple of questions:

I'm wondering if I can simply spin up 3-5 aws linux vm's and use the free version of splunk to get familiar with the process of creating a distributed enviro (assigning a search head, 1 idx, maybe couple of forwarders and a deployment server using the free splunk??? 

Or, is the free splunk Enterprise only good for 1 download on 1 machine ??

Thanks!


Labels (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

 

Yes you can setup multiple VMs for different Splunk role with Splunk Entrprise (which has 500MB license for 60 days).

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

 

Yes you can setup multiple VMs for different Splunk role with Splunk Entrprise (which has 500MB license for 60 days).

0 Karma

isoutamo
SplunkTrust
SplunkTrust
But you cannot use separate LM. Use local trial licenses in all nodes.
0 Karma

ragedsparrow
Contributor

Greetings,

Splunk Free is only available for a single, stand-alone instance.  You will be unable to build a distributed environment with a Splunk Free license.

0 Karma

ragedsparrow
Contributor

However, as previously mentioned, you could use the Splunk Enterprise Trial license to do what  you're wanting.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...