Installation

Event count is different after upgrading from a Free to Enterprise license

Ellen
Splunk Employee
Splunk Employee

We recently purchased Splunk and upgraded from a Free license to an Enterprise license.
After I installed the new license and restarted some of our indexes did not appear in the UI and our summary page shows a smaller event count.
What happened? All I did was install a new license?

Tags (3)
1 Solution

Jaci
Splunk Employee
Splunk Employee

The Splunk Free license is a single user product that does not use authentication or access controls. Indexes created with the Free license are not searchable because under the Enterprise license the admin role does not have permission.

To resolve this go to manager>>Access Controls>>Roles>>Admin and add the missing indexes to the "Indexes searched by default" list of selected indexes.

View solution in original post

paulahoffman
Explorer

Similar issue. I was using a temp Ent license. When it expired I installed a new Ent license and removed the temp license.

A couple of weeks later I found that the 'earliest event' under Manager/Indexes for this index was the same day I upgraded the license. I was unable to find any data other than 'summary_host' events for systems I searched for.
My system has multiple indexers. The searchhead was already configured as you suggested for the Manager/AccessControls/Roles/Admin to use the index. I updated an indexer to the same settings for Admin. However, the 'earliest event' did not change on the indexer.
Is the previous data (using the temp Ent license) still on the indexers or was it purged during the license update?
Thanks

0 Karma

Jaci
Splunk Employee
Splunk Employee

The Splunk Free license is a single user product that does not use authentication or access controls. Indexes created with the Free license are not searchable because under the Enterprise license the admin role does not have permission.

To resolve this go to manager>>Access Controls>>Roles>>Admin and add the missing indexes to the "Indexes searched by default" list of selected indexes.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...