Hi,
I have a Splunk Enterprise cluster that consists of:
1 cluster master
3 indexers
1 search head
1 license master
My doubt is: when the Enterprise license expires and you don't include a new license, what happens to the data already residing in the indexers? Does it remain accessible? Is there any specific procedure that I would need to perform to make sure the data would remain accessible in that situation?
As I understand it, Splunk lets you to downgrade to a Free license, and then you lose all the Enterprise features, including distributed search. Given that Free license doesn't allow distributed search, does this mean that the 3 indexers will automatically become standalone instances, and I'd still be able to search their data individually?
... View more