Installation

Splunk DEV/TEST License

sivakrishna
Path Finder

Hi Team,

1.We have the 50GB of DEV/TEST license file with us. After Configuring this License Can we create Knowledge objects like Dashboards, Reports and alerts.??

2. Do we have any restrictions after configuring the DEV/TES License that prevent us from performing these tasks with the DEV/TEST license? In comparison to Enterprise

3. I want to configure this on a single server that serves as Heavy Forwarder Search head and the indexer. This makes sense, right?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @sivakrishna,

you can find more details at:

https://www.youtube.com/@Splunkofficial

https://dev.splunk.com/enterprise/

https://www.splunk.com/en_us/resources/personalized-dev-test-licenses/faq.html 

anyway, answering to your questions:

1)

you can create Knowledge objects like Dashboards, Reports and alerts everyway, because you have a full istance license, the Splunk Features don't depend on the license, the license assure to you that your system continue to run also indexing more than 500 MB/day (Free License).

2)

for my knowledge no limit

3)

If you have a stand-alone Splunk server, you can install the license on it,

if instead you have a distributed architecture or a cluster, you have to install it in one server configured as License Master.

Only one question: if you have a stand-alone server, it has the role of Indexer and Search Head, but why do you want to give it also the role of Heavy Forwarder? it's useful to send events to another Splunk instance not to the same.

also because Universal Forwarders don't need a license, and Heavy Forwarders have their own license.

Ciao.

Giuseppe

View solution in original post

sivakrishna
Path Finder

Thanks, for the detailed Explanation.

Now I got You.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sivakrishna ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @sivakrishna,

you can find more details at:

https://www.youtube.com/@Splunkofficial

https://dev.splunk.com/enterprise/

https://www.splunk.com/en_us/resources/personalized-dev-test-licenses/faq.html 

anyway, answering to your questions:

1)

you can create Knowledge objects like Dashboards, Reports and alerts everyway, because you have a full istance license, the Splunk Features don't depend on the license, the license assure to you that your system continue to run also indexing more than 500 MB/day (Free License).

2)

for my knowledge no limit

3)

If you have a stand-alone Splunk server, you can install the license on it,

if instead you have a distributed architecture or a cluster, you have to install it in one server configured as License Master.

Only one question: if you have a stand-alone server, it has the role of Indexer and Search Head, but why do you want to give it also the role of Heavy Forwarder? it's useful to send events to another Splunk instance not to the same.

also because Universal Forwarders don't need a license, and Heavy Forwarders have their own license.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...