Hi,
My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?
I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.
I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.
What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.
Hey
Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances
3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.
Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree
Let me know if this helps you!
Hi,
I'm none of the above. No violations for the past 30 days.
are you getting messages like "you have exceeded your license limit too many times"?
nope. Only new version available message.
check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license