Installation

If Enterprise License Expires

Jnewman28
Explorer

Hello.

If our Enterprise Splunk license expired and we disabled our ingest, so no license violations were received, would Splunk historical data still be fully searchable, WITHOUT applying free license or applying another Enterprise license?

Thanks,

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't think so. The data would be of course untouched (but would still be subject to ageing and expiring) but I think the search functionality would be disabled until you produced a valid license.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jnewman28,

if you haven't any violation and you don't ingest new logs or you ingest less than 500 MB/day you can continue to access the indexed data with the only limit of the retention time (by default 6 years).

But using a free license some features are disabled (e.g. login, alerts, distributed search, etc...) as you can see at https://www.splunk.com/view/SP-CAAAE66

Ciao.

Giuseppe

0 Karma

Jnewman28
Explorer

Hi @gcusello 

To confirm, if we do not downgrade to the free license, and then our Enterprise license expires, will we still be able to search our previously indexed data, without a free license applied?

We are looking to have search functionality, and maintain login credentials. We would disable future indexing, so no additional data should be ingested and indexed at that time.

Thanks for your help.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jnewman28,

So, when a Splunk Enterprise License expires, you must downgrade to a Free license, the only other choice is to buy a new license!

As I said: using a free license some features are disabled (e.g. login, alerts, distributed search, etc...) as you can see at https://www.splunk.com/view/SP-CAAAE66

in addition you have the limit of 500 MB/day and 3 exceedings of the above limit.

So if you don't index other data, you can continue to search in all the indexed data until you have these data in your indexes (for this reason I spoke of retention!).

Beware: you don't have login credentials in the Free version, only in the licensed version!

Tell me if I can help you more, or, please, accept the answer for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...