Splunk Enterprise

How do I export logs that were sent to Splunk Light?

walderbachj1
Engager

We allowed our Splunk Light license to expire and moved to another logging solution. We would like to export the data Splunk has collected over the past year into something we can either import or at least read with a text editor or pipe into a tail command. I've seen other answers like this one: https://answers.splunk.com/answers/43442/how-to-export-logs-to-excel-or-text-file.html?utm_source=ty...

However, we cannot do any searches as it says we have exceeded our license. We have nothing sending logs to Splunk Light, but the customer service person I just spoke to basically said unless we pay for a license, all that data is locked away.

Are there any ways around this? I'm not telling my CTO to pay 5 grand just so we can access our own logs. Again, I'm not looking to cheat the indexing system, I just want to take my ball and go home.

Tags (2)
0 Karma

ddrillic
Ultra Champion
0 Karma

walderbachj1
Engager

I tried this but after install, the webUI just asks me to purchase a license and gives me less access than I had before. At least before I could see all the devices it had been collecting from and dates of last received data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...