Installation

After eval license expired, why am I no longer able to search old indexed data after converting to a perpetual free license?

gardnerwg64
New Member

I installed an evaluation for my Customer in a test environment, the license key expired and after a couple of weeks I managed to login and change the license for the test environment to a perpetual free license.

However for any of the original data that was indexed prior to the license expiration is not able to be searched, displayed etc.

Any ideas on why this has happened and how I can resolve the issue? By the way, my Customer has initiated a purchase order, but for now I cannot see any of the indexed information.

Labels (1)
Tags (2)
0 Karma

lseelbac
Engager

For the record, this appears to not entirely be true. What I found was that as soon as the Enterprise Trial expires, your licensed quota volume drops immediately to 0 bytes per day until you manually switch to the Free License pool. This means that instantly you are in license violation and if you do not make the switch within 3 days of the trial expiring, you are locked out of searching for the next 30 days. Frankly, not the brightest approach.

megawatt
New Member

This is exactly whats happening (and I have seen happen) and I think its totally stupid. Thanks for the aggravation Splunk.

0 Karma

NOUMSSI
Builder

Hi,

The Free license allows you a limited indexing volume and disables authentication, but is perpetual. This license includes 500 MB/day of indexing volume. So if you where indexing more than 500 MB/day before you changed the license for the test environment to a perpetual free license, now that you've change indexing has been stopped. When de indexing has be stopped, searches, display ... will be not able.

To resolve the issue, add a new license. Here is the procedure to add new license to splunk:

  1. Navigate to Settings > Licensing.
  2. Click Add license.
  3. Either click Choose file and browse for your license file and select it, or click copy & paste the license XML directly... and paste the text of your license file into the provided field.
  4. Click Install. If this is the first Enterprise license that you are installing, you must restart Splunk. Your license is installed.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...