Installation

Splunk unable to search auth.log after free trial expired?

wuming79
Path Finder

Hi,

My splunk free license has expired but I can still upload auth.log to splunk, however, I was not able to search anything after data is uploaded. I was also unable to search my old data. Is this normal?

0 Karma
1 Solution

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

View solution in original post

0 Karma

wuming79
Path Finder

I'm not sure why. I just upload my data again but changing the host from default "splunk" to some other names and it works now.

0 Karma

micahkemp
Champion

What do you see when you try to search? A screenshot is probably very valuable to help troubleshoot.

0 Karma

mayurr98
Super Champion

Hey

Let me tell you something about free license:
-- Disables alerts, authentication, clustering, distributed search,
summarization, and forwarding to non-Splunk servers
-- Allows 500mb/day of indexing and forwarding to other Splunk
instances

3 warnings on a Free license, in a rolling 30-day period, is a
violation.Thereafter you can not able to search any data though you can index it.

Refer this doc:
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/MoreaboutSplunkFree

Let me know if this helps you!

0 Karma

wuming79
Path Finder

Hi,

I'm none of the above. No violations for the past 30 days.

0 Karma

mayurr98
Super Champion

are you getting messages like "you have exceeded your license limit too many times"?

0 Karma

wuming79
Path Finder

nope. Only new version available message.

0 Karma

mayurr98
Super Champion

check if its a trial license or free license ? trial is valid for 60 days thereafter you need to activate it as a free license

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...