Splunk Enterprise

How do I export logs that were sent to Splunk Light?


We allowed our Splunk Light license to expire and moved to another logging solution. We would like to export the data Splunk has collected over the past year into something we can either import or at least read with a text editor or pipe into a tail command. I've seen other answers like this one: https://answers.splunk.com/answers/43442/how-to-export-logs-to-excel-or-text-file.html?utm_source=ty...

However, we cannot do any searches as it says we have exceeded our license. We have nothing sending logs to Splunk Light, but the customer service person I just spoke to basically said unless we pay for a license, all that data is locked away.

Are there any ways around this? I'm not telling my CTO to pay 5 grand just so we can access our own logs. Again, I'm not looking to cheat the indexing system, I just want to take my ball and go home.

Tags (2)
0 Karma

Ultra Champion
0 Karma


I tried this but after install, the webUI just asks me to purchase a license and gives me less access than I had before. At least before I could see all the devices it had been collecting from and dates of last received data.

0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...