Splunk Enterprise

Splunk free license usage.



I setup a test server last year. Forgot about it till this year.
Nothing is sending data to splunk. There's no information in there.
Logged in and cannot use the search.
The trial license expired. So I switched license group to free.
Using the web front end. I logged in again, and can still not use the search.
I left it as is yesterday, thinking it needed a day to tick over.
Came in this morning, logged in, and search still does not work.

[EventsViewer module] Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.

I am an existing customer. Just looking to setup another testing environment.


Splunk Employee
Splunk Employee

You can just download a new version of Splunk and install it as your test environment if you do not care about any of the old data in that system. Move your existing configuration files over if they are still valid. YOu will have the full trial for 60 days and you can then convert to the free license.

Here's a good view of the differences once you convert to the free verssion.


0 Karma


If you logged in to your search head it's not using the free license.


Installed Splunk License Usage plugin.
Here are the results for the past 24 hours:

metrics.log 20011.250816
scheduler.log 2253.667978
audittrail 1557.134735
web_access.log 1460.388676
splunkd.log 1357.563526
splunkd_access.log 1254.835952
web_service.log 157.104491
df 68.437500
license_usage.log 56.928728
searches.log 8.151366
splunkd_stdout.log 3.211914
metrics.log.1 2.607422
license_audit.log 0.557617
splunkd_stderr.log 0.498048
intentions.log 0.440430

Does not look anywhere near 500MB.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!