FAQ

 


General Information
Company Background
Purchasing Splunk
Splunk Base and the Splunk Community
Customers and Partners
Getting Started
How Splunk Handles Data
Administration
Integrating and Extending Splunk
Troubleshooting
Getting Help

Licensing

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Licensing

What are the differences between the free and enterprise licenses?

Splunk will run with a free license which allows you to index up to 500 MB/day, or you can buy an enterprise license to get higher data volumes, additional features, and support. You can also register for a free 30-day trial enterprise license. Best of all there's just one download and just one software package - just drop in an enterprise license to enable the enterprise features!


For a complete breakdown of the differences click here.


What happens when my trial license expires?

Splunk will continue to index data but search will be blocked until you plug in a new license.


Does indexing stop if I reach the limit of my license?

No. Splunk will always index the data. If you exceed your license limit a violation will be recorded.


What happens when I exceed my license limit?

Splunk allows up to a set number of violation days in a rolling 30-day period, since we know that sometimes you'll have an unpredictable one-time spike. For 3.0 the limit is 7 violations in the 30-day period. If you exceed the limit more than the allowed number of days, searches will be blocked. You will see warnings starting with the first violation before then, and then the notice that searches are blocked. The violation banner will persist for 7 days from the last violation. In any case, indexing will continue since we don't want you to lose data. You can start searching again as soon as a full day passes that stays within the allowed volume, or you enter a new license.


My 2.x license doesn't work with 3.0

Version 3 introduces a new license key format. If you are an existing 2.x customer your license will not work with 3.0. Plus Support customers are entitled to upgrade their 2.x license to 3.0. Please contact Splunk Support for your 3.0 license.

This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.