Deployment Architecture

how many forwarders does the splunk free version support?

tanzic
New Member

I installed one splunk trial version and two universal forwarders on different servers. they all worked normally at the beginning. The splunk server could get the data from the two forwarders. But one month later, the splunk server can get only one forwarder data. And the status of splunk server and two forwarders are normal. Currently the splunk version is free. so my question is how many forwarders does the splunk free version support? only one ? If not , what should i do to fix the problem so that i can get both forwarders data? Thank you in advance.

0 Karma
1 Solution

sandeepmakkena
Contributor

You will have only 30 days of free trail version. You can refer this https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/MoreaboutSplunkFree

I think you can uninstall and reinstall which should give you another free trail. I'm not sure about it.

View solution in original post

0 Karma

amitm05
Builder

@tanzic
There is no limit stated by Splunk on the number for forwarders used with Free Splunk. So, I'll say you can go ahead and use as my UFs you want to use. It is only about the license usage which should remain within 500 MB and ofcourse it would be a 30 day trial period.

Thanks.

0 Karma

sandeepmakkena
Contributor

You will have only 30 days of free trail version. You can refer this https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/MoreaboutSplunkFree

I think you can uninstall and reinstall which should give you another free trail. I'm not sure about it.

0 Karma

spectrum2035
Explorer

I am not aware off any limits on UF which can be used. The only limit is on license.

Other limits are:

  1. Distributed search configurations (including search head clustering) are not available.
  2. Forwarding in TCP/HTTP formats is not available. This means you can forward data to other Splunk platform instances, but not to non-Splunk software.
  3. Deployment management capabilities are not available.
  4. Alerting (monitoring) is not available.
  5. Indexer clustering is not available.
  6. Report acceleration summaries are not available.
  7. While a Splunk Free instance can be used as a forwarder (to a Splunk Enterprise indexer) it cannot be the client of a deployment server.
  8. There is no authentication or user and role management when using Splunk Free. This means:
  9. There is no login. The command line or browser can access and control all aspects of Splunk Free with no user and password prompt.
  10. All accesses are treated as equivalent to the admin user. There is only one role (admin), and it is not configurable. You cannot add more roles or create user accounts.
  11. Searches are run against all public indexes, 'index=*'.
  12. Restrictions on search, such as user quotas, maximum per-search time ranges, and search filters, are not supported.
  13. The capability system is disabled. All available capabilities are enabled for all users accessing Splunk Free.
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...