Hi, 
 I have a Splunk Enterprise cluster that consists of: 
 
 1 cluster master 
 3 indexers 
 1 search head 
 1 license master 
 
 My doubt is: when the Enterprise license expires and you don't include a new license, what happens to the data already residing in the indexers? Does it remain accessible? Is there any specific procedure that I would need to perform to make sure the data would remain accessible in that situation? 
 As I understand it, Splunk lets you to downgrade to a Free license, and then you lose all the Enterprise features, including distributed search. Given that Free license doesn't allow distributed search, does this mean that the 3 indexers will automatically become standalone instances, and I'd still be able to search their data individually? 
						
					
					... View more