Installation

What happens to Splunk if annual term enterprise license expires?

melonman
Motivator

Hi

I am looking for the detailed information of Splunk behavior when Splunk annual term enterprise license expires.

  • Enter a new term license or forced to switch to Free license?
  • Does Indexing Stop?
  • What happens for enterprise features e.g. distributed searches, access control with multiple users ...

Any pointer to the information would be appreciated.

Labels (2)
1 Solution

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

tbaublys_splunk
Splunk Employee
Splunk Employee

Are you sure the indexing will be limited to 500MB after expiration? If I have a production with let's say 100GB License / Term and this expires, I would expect the search being disabled but indexing continued.

0 Karma

melonman
Motivator

What the answer says: indexing will not stop, but the license will be reverted to 500MB if you choose to free. and the behavior of the latest Splunk version may be different from older version.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

melonman
Motivator

Thank you, so Does Splunk behaves the same when facing violations and when facing license expirations?

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...