Splunk Enterprise

How do I export logs that were sent to Splunk Light?

walderbachj1
Engager

We allowed our Splunk Light license to expire and moved to another logging solution. We would like to export the data Splunk has collected over the past year into something we can either import or at least read with a text editor or pipe into a tail command. I've seen other answers like this one: https://answers.splunk.com/answers/43442/how-to-export-logs-to-excel-or-text-file.html?utm_source=ty...

However, we cannot do any searches as it says we have exceeded our license. We have nothing sending logs to Splunk Light, but the customer service person I just spoke to basically said unless we pay for a license, all that data is locked away.

Are there any ways around this? I'm not telling my CTO to pay 5 grand just so we can access our own logs. Again, I'm not looking to cheat the indexing system, I just want to take my ball and go home.

Tags (2)
0 Karma

ddrillic
Ultra Champion
0 Karma

walderbachj1
Engager

I tried this but after install, the webUI just asks me to purchase a license and gives me less access than I had before. At least before I could see all the devices it had been collecting from and dates of last received data.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...