Installation

What happens to Splunk if annual term enterprise license expires?

melonman
Motivator

Hi

I am looking for the detailed information of Splunk behavior when Splunk annual term enterprise license expires.

  • Enter a new term license or forced to switch to Free license?
  • Does Indexing Stop?
  • What happens for enterprise features e.g. distributed searches, access control with multiple users ...

Any pointer to the information would be appreciated.

Labels (2)
1 Solution

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

tbaublys_splunk
Splunk Employee
Splunk Employee

Are you sure the indexing will be limited to 500MB after expiration? If I have a production with let's say 100GB License / Term and this expires, I would expect the search being disabled but indexing continued.

0 Karma

melonman
Motivator

What the answer says: indexing will not stop, but the license will be reverted to 500MB if you choose to free. and the behavior of the latest Splunk version may be different from older version.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

melonman
Motivator

Thank you, so Does Splunk behaves the same when facing violations and when facing license expirations?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...