I recently downloaded Splunk. Right now, I am using the free license that came with Splunk software on three different servers. Is that ok? Or do I need a different free license for each instance of Splunk I have? If so, how do I get more free licenses?
I can also use forwarding with the free version of Splunk, correct? And how much data can I forward with the free version?
I'd suggest that you check out http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree for a lot more details about the Free vs Enterprise.
But, to answer your specific questions:
I found this link that talk about the features that you lost when use a Free license.
http://docs.splunk.com/Documentation/Splunk/4.3/Admin/TypesofSplunklicenses#Free_license
I'd suggest that you check out http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree for a lot more details about the Free vs Enterprise.
But, to answer your specific questions:
So i could index 50GB in a single time and not be limited as i only did it once ?
Suppose i do get limited i can search that data after my searching gets re-enabled ?
How long is searching disabled ?
You can only index 1 Mb a day locally. But in forwarder mode, you are forwarding all your data to another indexer, so nothing should be indexed locally, so the "1 MB limit" really doesn't limit you in any way.
I'd say no, otherwise I'd be in trouble since I forward gigs a day using the free license 🙂
Thanks for the help! The main issue I have with using the the forward license is that it says I can only forward up to 1 MB per day. Any truth to that?