Installation

Splunk unable to search auth.log after free trial expired?

wuming79
Path Finder

Hi,

My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?

0 Karma
1 Solution

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

0 Karma

micahkemp
Champion

What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.

0 Karma

mayurr98
Super Champion

Hey

Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances

3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.

Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree

Let me know if this helps you!

0 Karma

wuming79
Path Finder

Hi,

I'm none of the above. No violations for the past 30 days.

0 Karma

mayurr98
Super Champion

are you getting messages like "you have exceeded your license limit too many times"?

0 Karma

wuming79
Path Finder

nope. Only new version available message.

0 Karma

mayurr98
Super Champion

check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...