Installation

What happens to Splunk if annual term enterprise license expires?

melonman
Motivator

Hi

I am looking for the detailed information of Splunk behavior when Splunk annual term enterprise license expires.

  • Enter a new term license or forced to switch to Free license?
  • Does Indexing Stop?
  • What happens for enterprise features e.g. distributed searches, access control with multiple users ...

Any pointer to the information would be appreciated.

Labels (2)
1 Solution

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee
  1. When your license expires, you can either apply a new term license, or switch to a free license.
  2. Indexing will not stop, but you will be limited to the daily indexing volume of the license you choose (500MB for free license). Search will only be disabled after you exceed the documented number of license violations (different for free and enterprise)
  3. If you are choosing to switch to a free license, enterprise features will no longer work. See here for limitations of the free license.

tbaublys_splunk
Splunk Employee
Splunk Employee

Are you sure the indexing will be limited to 500MB after expiration? If I have a production with let's say 100GB License / Term and this expires, I would expect the search being disabled but indexing continued.

0 Karma

melonman
Motivator

What the answer says: indexing will not stop, but the license will be reverted to 500MB if you choose to free. and the behavior of the latest Splunk version may be different from older version.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

melonman
Motivator

Thank you, so Does Splunk behaves the same when facing violations and when facing license expirations?

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...