I installed an evaluation for my Customer in a test environment, the license key expired and after a couple of weeks I managed to login and change the license for the test environment to a perpetual free license.
However for any of the original data that was indexed prior to the license expiration is not able to be searched, displayed etc.
Any ideas on why this has happened and how I can resolve the issue? By the way, my Customer has initiated a purchase order, but for now I cannot see any of the indexed information.
For the record, this appears to not entirely be true. What I found was that as soon as the Enterprise Trial expires, your licensed quota volume drops immediately to 0 bytes per day until you manually switch to the Free License pool. This means that instantly you are in license violation and if you do not make the switch within 3 days of the trial expiring, you are locked out of searching for the next 30 days. Frankly, not the brightest approach.
This is exactly whats happening (and I have seen happen) and I think its totally stupid. Thanks for the aggravation Splunk.
Hi,
The Free license allows you a limited indexing volume and disables authentication, but is perpetual. This license includes 500 MB/day of indexing volume. So if you where indexing more than 500 MB/day before you changed the license for the test environment to a perpetual free license, now that you've change indexing has been stopped. When de indexing has be stopped, searches, display ... will be not able.
To resolve the issue, add a new license. Here is the procedure to add new license to splunk: