Installation

If Enterprise License Expires

Jnewman28
Explorer

Hello.

If our Enterprise Splunk license expired and we disabled our ingest, so no license violations were received, would Splunk historical data still be fully searchable, WITHOUT applying free license or applying another Enterprise license?

Thanks,

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't think so. The data would be of course untouched (but would still be subject to ageing and expiring) but I think the search functionality would be disabled until you produced a valid license.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jnewman28,

if you haven't any violation and you don't ingest new logs or you ingest less than 500 MB/day you can continue to access the indexed data with the only limit of the retention time (by default 6 years).

But using a free license some features are disabled (e.g. login, alerts, distributed search, etc...) as you can see at https://www.splunk.com/view/SP-CAAAE66

Ciao.

Giuseppe

0 Karma

Jnewman28
Explorer

Hi @gcusello 

To confirm, if we do not downgrade to the free license, and then our Enterprise license expires, will we still be able to search our previously indexed data, without a free license applied?

We are looking to have search functionality, and maintain login credentials. We would disable future indexing, so no additional data should be ingested and indexed at that time.

Thanks for your help.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jnewman28,

So, when a Splunk Enterprise License expires, you must downgrade to a Free license, the only other choice is to buy a new license!

As I said: using a free license some features are disabled (e.g. login, alerts, distributed search, etc...) as you can see at https://www.splunk.com/view/SP-CAAAE66

in addition you have the limit of 500 MB/day and 3 exceedings of the above limit.

So if you don't index other data, you can continue to search in all the indexed data until you have these data in your indexes (for this reason I spoke of retention!).

Beware: you don't have login credentials in the Free version, only in the licensed version!

Tell me if I can help you more, or, please, accept the answer for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...