Hi,
Splunk Enterprise Trial gives you access to a number of features that are not available in Splunk Free. When you switch, be aware of the following:
User accounts or roles that you created no longer work.
Anyone connecting to the instance will automatically be logged on as admin. You will no longer see a login screen, though you will see the update check occur.
Any knowledge objects created by any user other than admin (such as event type, transaction, or source type definitions) and not already globally shared will not be available. If you need these knowledge objects to continue to be available after you switch to Splunk Free, you can do one of the following:
Use Splunk Web to promote them to be globally available before you switch. See Manage app and add-on objects.
Hand edit the configuration files they are in to promote them. See App architecture and object ownership.
Any alerts you defined no longer trigger. You no longer receive alerts from Splunk software. You can still schedule searches to run for dashboards and summary indexing purposes.
Configurations in outputs.conf to forward to third-party applications in TCP or HTTP formats do not work.
When you switch to splunk free from a Trail Enterprise license follow the steps below:
Log in to Splunk Web as a user with admin privileges and navigate to Settings > Licensing.
Click Change license group at the top of the page.
Select Free license and click Save.
You are prompted to restart.
You can also go through the link of splunk documentation below:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/HowSplunklicensingworks
... View more