Hey Splunk support,
Can you direct me on how to get my free license reset?
I thought I was running the free version but apparently it was an Enterprise trial which expired. I'd like to activate the free version again so I don't lose the data I've collected.
I am having kind of the same issue here.
I don't know why my free licence is expired, I suddenly have the following message :
Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.
I did not exceed my 500Mb quota, as last time I checked I barely used 5% of it.
Is it possible there is a problem with splunk's licencing system?
What sould I do to have my splunk usable again?
Did you check under Settings > Licensing if the license is not expired? Normally its about 60 days.
Local server information Indexer name <your license host> License expiration Jan 5, 2018 4:24:12 PM Licensed daily volume 500 MB Volume used today 3 MB (0.677% of quota) Warning count 0 Debug information All license details All indexer details
When you install Splunk, you start off on the Splunk Enterprise Trial. After 60 days this trial expires, and you have to convert to the Free licence which has a few limitations.
You can tell if your are on an Enterprise(Trial) Vs Free licence by opening Splunk.
If you are prompted to Login, you are on the Enterprise (Trial)
However if you get access without providing any credentials, then you are running the Free version.
As per the accepted answer in this thread.
The documentation explains how to
switch to Splunk Free from an
Enterprise trial license. It's in
Manager > License > Change license
However, If you have violated the licence you may be looking at a backup/reinstall to clear the violations (or wait 30 days since your last violation)
Generally you aren't likely to get a reset license for a free version of Splunk, the best way to bypass the violations is to backup your indexes, delete, reinstall and copy the indexes back over.
However, when I went back to the free license the violations are still there preventing the search function from working. The only solution I've seen is to get a license reset from Splunk support directly.