Deployment Architecture

Will I be able to index 500MB of data daily with Splunk free version?

simtcr
Engager

I am downloaded and installed Splunk enterprise at home without procuring a license.

Is my below understanding correct?

 

I will be able to index 500MB data daily.

As long as I stay under that limit, I should be able to use splunk forever.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @simtcr,

yes, you can use it forever with the main limit of 500 MB/day of indexed data and the possibility to exceed this limit 2 times every 30 solar days.

In the first 60 days, you'll have the full Splunk Enterprise features, but after these time you lose some features, e.g. the login and the distributed search, for more infos see at https://docs.splunk.com/Documentation/Splunk/9.0.3/Admin/TypesofSplunklicenses

Ciao.

Giuseppe

View solution in original post

0 Karma

brutha_analog
Explorer

Hi new Splunk wannabe over here.

I'm trying to learn SPLUNK in my spare time and on my own dime. I have been taking the free classes on the learning paths. I want to get CORE CERTIFIED in about 30 days(end of Feb.). Is this FREE SPLUNK suitable to teach myself? In other words, I won't have any live data to do searches. 

Thanks.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @brutha_analog,

at first, it's always better to open a new question instead add to another one, in this way you limit your choices to have a quick and better answer.

Then, using the Free license you have a full Splunk environment for 60 days with the only limit of indexing max 500 MB/day, but for testing it should be sufficient.

If you need sources or testing, you can access (and I hint to do it) the Splunk Search Tutorial (https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial) that theaches you in searching and gives you the tutorial data.

About line data, you can also use the os log from your machine.

Ciao.

Giuseppe

0 Karma

simtcr
Engager

Thank you @gcusello

I just changed license group to "Free license group" and saw that lost login feature.

I submitted a developer license request (which is under review now) I hope that give more flexibility for 6 months and is also renewable.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just remember that Developer license is not meant to be for "I just want to have full Splunk Enterprise at home" use.

It's meant for the users who indeed do develop apps/add-ons in their spare time and need a full license for testing the functionality. So if you just need a home Splunk installation for private use, just stick to the Free license and don't abuse the Developer license please.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @simtcr,

yes, it should solve your need.

if one answer solves your need, please accept one answer for the other people of Community or tell me how Ican help you more.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @simtcr,

yes, you can use it forever with the main limit of 500 MB/day of indexed data and the possibility to exceed this limit 2 times every 30 solar days.

In the first 60 days, you'll have the full Splunk Enterprise features, but after these time you lose some features, e.g. the login and the distributed search, for more infos see at https://docs.splunk.com/Documentation/Splunk/9.0.3/Admin/TypesofSplunklicenses

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...