Getting Data In

Will I still be able to forward data into the instance and create searches after the Enterprise trial ends?

Zamoraw
New Member

I currently have an Enterprise trial license and was wondering what would happen after the trial ends. Will I still be able to forward data into the instance and create searches?

0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

@zamoraw,

you need to switch your Spunk Enterprise trail license to free license after trail expires.

since you have daily index volume 500 MB in free license, I think you can forward data to Splunk Enterprise after Splunk Enterprise trail expires with trial license.

Below is what Splunk Documentation says and its no where mentioned that Splunk Enterprise does not receive data with trial license.

What you should know about switching to Free

Splunk Enterprise Trial gives you access to a number of features that are not available in Splunk Free. When you switch, be aware of the following:

User accounts or roles that you have created will no longer work.
Anyone connecting to the instance will automatically be logged on as admin. You will no longer see a login screen, though you will see the update check occur.
Any knowledge objects created by any user other than admin (such as event type, transaction, or source type definitions) and not already globally shared will not be available. If you need these knowledge objects to continue to be available after you switch to Splunk Free, you can do one of the following:
Use Splunk Web to promote them to be globally available before you switch. See Manage app and add-on objects.
Hand edit the configuration files they are in to promote them. See App architecture and object ownership.
Any alerts you have defined will no longer trigger. You will no longer receive alerts from Splunk software. You can still schedule searches to run for dashboards and summary indexing purposes.
Configurations in outputs.conf to forward to third-party applications in TCP or HTTP formats will stop working.
When you attempt to make any of the above configurations in Splunk Web while using an Enterprise Trial license, you will be warned about the above limitations in Splunk Free.

Free Splunk

————————————
If this helps, give a like below.

View solution in original post

0 Karma

woodcock
Esteemed Legend

When the free license expires, everything shuts down and you need a Dev or Paid license to get back in. The easiest thing to do is get a Dev license (dev.splunk.com); it is free and takes a few days after you request one by email. You can also uninstall and reinstall Splunk.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@zamoraw,

you need to switch your Spunk Enterprise trail license to free license after trail expires.

since you have daily index volume 500 MB in free license, I think you can forward data to Splunk Enterprise after Splunk Enterprise trail expires with trial license.

Below is what Splunk Documentation says and its no where mentioned that Splunk Enterprise does not receive data with trial license.

What you should know about switching to Free

Splunk Enterprise Trial gives you access to a number of features that are not available in Splunk Free. When you switch, be aware of the following:

User accounts or roles that you have created will no longer work.
Anyone connecting to the instance will automatically be logged on as admin. You will no longer see a login screen, though you will see the update check occur.
Any knowledge objects created by any user other than admin (such as event type, transaction, or source type definitions) and not already globally shared will not be available. If you need these knowledge objects to continue to be available after you switch to Splunk Free, you can do one of the following:
Use Splunk Web to promote them to be globally available before you switch. See Manage app and add-on objects.
Hand edit the configuration files they are in to promote them. See App architecture and object ownership.
Any alerts you have defined will no longer trigger. You will no longer receive alerts from Splunk software. You can still schedule searches to run for dashboards and summary indexing purposes.
Configurations in outputs.conf to forward to third-party applications in TCP or HTTP formats will stop working.
When you attempt to make any of the above configurations in Splunk Web while using an Enterprise Trial license, you will be warned about the above limitations in Splunk Free.

Free Splunk

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...