Installation

Splunk unable to search auth.log after free trial expired?

wuming79
Path Finder

Hi,

My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?

0 Karma
1 Solution

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

0 Karma

micahkemp
Champion

What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.

0 Karma

mayurr98
Super Champion

Hey

Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances

3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.

Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree

Let me know if this helps you!

0 Karma

wuming79
Path Finder

Hi,

I'm none of the above. No violations for the past 30 days.

0 Karma

mayurr98
Super Champion

are you getting messages like "you have exceeded your license limit too many times"?

0 Karma

wuming79
Path Finder

nope. Only new version available message.

0 Karma

mayurr98
Super Champion

check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...