Splunk Enterprise

How do I export logs that were sent to Splunk Light?

walderbachj1
Engager

We allowed our Splunk Light license to expire and moved to another logging solution. We would like to export the data Splunk has collected over the past year into something we can either import or at least read with a text editor or pipe into a tail command. I've seen other answers like this one: https://answers.splunk.com/answers/43442/how-to-export-logs-to-excel-or-text-file.html?utm_source=ty...

However, we cannot do any searches as it says we have exceeded our license. We have nothing sending logs to Splunk Light, but the customer service person I just spoke to basically said unless we pay for a license, all that data is locked away.

Are there any ways around this? I'm not telling my CTO to pay 5 grand just so we can access our own logs. Again, I'm not looking to cheat the indexing system, I just want to take my ball and go home.

Tags (2)
0 Karma

ddrillic
Ultra Champion
0 Karma

walderbachj1
Engager

I tried this but after install, the webUI just asks me to purchase a license and gives me less access than I had before. At least before I could see all the devices it had been collecting from and dates of last received data.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...