Will the Ossec app (ver Version 1.1.77) run under a trial version of Splunk 4.1?
Please and Thanks, Mike
Since the trial license enables Enterprise features, it will work fine as long as you do not go over the 500 MB per day indexing cap on the trial license.
There are a few things that will not work with the free license, primarily because the Free version does not allow scheduled searches.
Mainly this affects the summary indexing views and tracking of any new servers. For the latter, you can always run the "Rebuild Server Lookup Table" from the Searches and Reports -> Utility menu.
Thanks.
Having some issues getting it to work and wanted to eliminate the licence issue.
Any app on splunkbase (with exception for the pay apps, like Splunk PCI) will work with the 30 day trial license.