Deployment Architecture

how many forwarders does the splunk free version support?

tanzic
New Member

I installed one splunk trial version and two universal forwarders on different servers. they all worked normally at the beginning. The splunk server could get the data from the two forwarders. But one month later, the splunk server can get only one forwarder data. And the status of splunk server and two forwarders are normal. Currently the splunk version is free. so my question is how many forwarders does the splunk free version support? only one ? If not , what should i do to fix the problem so that i can get both forwarders data? Thank you in advance.

0 Karma
1 Solution

sandeepmakkena
Contributor

You will have only 30 days of free trail version. You can refer this https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/MoreaboutSplunkFree

I think you can uninstall and reinstall which should give you another free trail. I'm not sure about it.

View solution in original post

0 Karma

amitm05
Builder

@tanzic
There is no limit stated by Splunk on the number for forwarders used with Free Splunk. So, I'll say you can go ahead and use as my UFs you want to use. It is only about the license usage which should remain within 500 MB and ofcourse it would be a 30 day trial period.

Thanks.

0 Karma

sandeepmakkena
Contributor

You will have only 30 days of free trail version. You can refer this https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/MoreaboutSplunkFree

I think you can uninstall and reinstall which should give you another free trail. I'm not sure about it.

0 Karma

spectrum2035
Explorer

I am not aware off any limits on UF which can be used. The only limit is on license.

Other limits are:

  1. Distributed search configurations (including search head clustering) are not available.
  2. Forwarding in TCP/HTTP formats is not available. This means you can forward data to other Splunk platform instances, but not to non-Splunk software.
  3. Deployment management capabilities are not available.
  4. Alerting (monitoring) is not available.
  5. Indexer clustering is not available.
  6. Report acceleration summaries are not available.
  7. While a Splunk Free instance can be used as a forwarder (to a Splunk Enterprise indexer) it cannot be the client of a deployment server.
  8. There is no authentication or user and role management when using Splunk Free. This means:
  9. There is no login. The command line or browser can access and control all aspects of Splunk Free with no user and password prompt.
  10. All accesses are treated as equivalent to the admin user. There is only one role (admin), and it is not configurable. You cannot add more roles or create user accounts.
  11. Searches are run against all public indexes, 'index=*'.
  12. Restrictions on search, such as user quotas, maximum per-search time ranges, and search filters, are not supported.
  13. The capability system is disabled. All available capabilities are enabled for all users accessing Splunk Free.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...