Installation

Splunk unable to search auth.log after free trial expired?

wuming79
Path Finder

Hi,

My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?

0 Karma
1 Solution

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

0 Karma

micahkemp
Champion

What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.

0 Karma

mayurr98
Super Champion

Hey

Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances

3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.

Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree

Let me know if this helps you!

0 Karma

wuming79
Path Finder

Hi,

I'm none of the above. No violations for the past 30 days.

0 Karma

mayurr98
Super Champion

are you getting messages like "you have exceeded your license limit too many times"?

0 Karma

wuming79
Path Finder

nope. Only new version available message.

0 Karma

mayurr98
Super Champion

check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...