Installation

Why has the search function stopped working in Splunk trial version?

lucamarc
Path Finder

Is it really a good idea to have the violation limit in a trial version and cripple your own software? A few days ago my boss was trying to show Splunk Enterprise to his boss, but surprise, the search function had stopped working.

It's a trial version, isn't it? To make things worse, we had no idea that a hard limit existed in the first place, at first just thought that the search was somehow broken, and the error message didn't help much either:

Peer SPLUNK's search ended prematurely. Attempting to reconnect and resume.

No reference to the search function being disabled because of license "violations".

0 Karma

ChrisG
Splunk Employee
Splunk Employee

You can switch to the free license when the trial license expires. You might also want to read Types of Splunk licenses if you haven't already.

Totally agree about the error message. It should say something about the license violation. Did you have any notification about that in the Messages menu?

lucamarc
Path Finder

Well, I guess it was observation / feedback, more than a specific question. However, some questions come to mind:

  1. Why is Splunk implemented such an draconian license enforcement system on an evaluation version?
  2. Since this is enforced in the eval. version, why is this limitation not made more obvious in the initial documentation (possibly even stating it in the emails from the sales rep)?
  3. Why isn't this mentioned on every admin login, even after just one warning? I don't remember reading about the search function eventually being disabled with any of the warnings, or in the messages menu, or upon logging in; I think I would have noticed at least in same cases, but maybe I missed all of them
  4. Why, after the search block occurs, the only obvious error message that you get upon searches returning zero items is "Peer SPLUNK's search ended prematurely. Attempting to reconnect and resume"? Would a banner such as "The search function has been disabled due to excessive number of traffic warnings, see this URL in the documentation for info" be too on the nose?

Thanks,
Luca

0 Karma

lguinn2
Legend

This doesn't really seem like a question, and further, there is nothing that the Splunk community can do to help.
If you are unhappy with the free trial, perhaps you could mention that to a sales person.

0 Karma

pstickne
Explorer

I downvoted this post because this is a valid question to a valid problem. comments are not answers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...