Getting Data In

FREE Splunk that permits up to 500MB volume per day. How do I obtain this?

agoktas
Communicator

Hello!

How do I obtain a free version of Splunk that permits up to 500MB volume per day maximum? Is this something that I need to contact Splunk sales for (to obtain a license key)?

I have downloaded the enterprise version and it cuts you off after 30 days.

I just need the version/license for something I can keep indefinitely as I practice my SpunkFu at home/non-work time. At work, we have a licensed copy, but never bothered to have a FREE version for testing purposes.

Thanks in advance!

Tags (1)
0 Karma
1 Solution

niketn
Legend

@agoktas, Open Splunk and go to Settings > Licensing > Change license Group. Refer to Splunk documentation to change to Free license: http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree

By default License is Enterprise Trial License which you need to convert to Free license group. Following are the options you should see. Refer to documentation for details on various types of Splunk licenses: http://docs.splunk.com/Documentation/Splunk/latest/Admin/TypesofSplunklicenses

Enterprise license

This license adds support for multi-user and distributed deployments, alerting, role-based security, single sign-on, scheduled PDF delivery, and unlimited data volumes.

There are no valid Splunk Enterprise licenses installed. You will be prompted to install a license if you choose this option.

Forwarder license

Use this group when configuring Splunk as a forwarder.Learn more

Free license

Use this group when you are running Splunk Free. This license has a 500MB/day daily indexing volume. Learn more

Enterprise Trial license

This is your included download trial. IMPORTANT: If you switch to another license, you cannot return to the Trial. You must install an Enterprise license or switch to Splunk Free.

I don't remember whether Splunk Licensing itself is covered as a topic for Splunk Fundamentals Part 1, but it surely is a very important topic that you should be aware for learning Splunk. Do go through Splunk Documentation to understand the concepts.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@agoktas, Open Splunk and go to Settings > Licensing > Change license Group. Refer to Splunk documentation to change to Free license: http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree

By default License is Enterprise Trial License which you need to convert to Free license group. Following are the options you should see. Refer to documentation for details on various types of Splunk licenses: http://docs.splunk.com/Documentation/Splunk/latest/Admin/TypesofSplunklicenses

Enterprise license

This license adds support for multi-user and distributed deployments, alerting, role-based security, single sign-on, scheduled PDF delivery, and unlimited data volumes.

There are no valid Splunk Enterprise licenses installed. You will be prompted to install a license if you choose this option.

Forwarder license

Use this group when configuring Splunk as a forwarder.Learn more

Free license

Use this group when you are running Splunk Free. This license has a 500MB/day daily indexing volume. Learn more

Enterprise Trial license

This is your included download trial. IMPORTANT: If you switch to another license, you cannot return to the Trial. You must install an Enterprise license or switch to Splunk Free.

I don't remember whether Splunk Licensing itself is covered as a topic for Splunk Fundamentals Part 1, but it surely is a very important topic that you should be aware for learning Splunk. Do go through Splunk Documentation to understand the concepts.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...