Splunk® Enterprise

Admin Manual

Download manual as PDF

Download topic as PDF

Groups, stacks, pools, and other terminology

You can aggregate compatible Splunk Enterprise licenses into stacks of available license volume. You can also define pools of indexers to use license volume from a given stack.

Note: Stacks and pools are not available with the Free or Enterprise Trial licenses.

To understand the types of licenses, see Types of Splunk software licenses.

License terms diagram


Certain types of Splunk licenses can be aggregated together, or stacked so that the available license volume is the sum of the volumes of the individual licenses. This allows you to increase indexing volume capacity over timewithout needing to swap out licenses. Instead, you simply purchase additional capacity and add it to the appropriate stack.

Enterprise licenses and Sales Trial licenses can be stacked together and with each other. This includes a "no-enforcement" Enterprise license.

Stacks are unavailable with these license types:

  • Enterprise Trial
  • Free
  • Dev/Test. If you install a Dev/Test license over an Enterprise license, the Enterprise license will be deleted.
  • Forwarder


A license group contains one or more stacks. A stack can be a member of only one group, and only one group can be "active" in your Splunk installation at a time. Specifically this means that a given license master can only administer pools of licenses of one group type at a time. The groups are:

  • Enterprise/sales trial group -- This group allows stacking of purchased Enterprise licenses, and sales trial licenses (which are Enterprise licenses with a set expiry date, NOT the same thing as the downloaded Enterprise trial).
  • Enterprise trial group -- This is the default group when you first install a new Splunk platform instance. You cannot combine multiple Enterprise trial licenses into a stack and create pools from it. If you switch to a different group, you will not be able to switch back to the Enterprise trial group.
  • Free group -- This group exists to accommodate Splunk Free installations. When an Enterprise trial license expires after 60 days, that Splunk instance is converted to the Free group. You cannot combine multiple Splunk Free licenses into a stack and create pools from it.
  • Forwarder group -- This group exists for the purposes of configuring a Splunk instance as a universal forwarder or light forwarder. These types of forwarders do not perform any indexing, and therefore aren't really managed via the Licensing pages in Manager, but do belong to a license group. If you change the license group of a Splunk instance to the Forwarder group, it assumes that Splunk instance is configured as a forwarder and will not be indexing any data. See forwarders and "Forwarder licenses" for more information.


A subgroup can have one of several values, including DevTest or Production. You cannot stack two licenses with different subgroups.

Subgroups are introduced in Splunk Enterprise 6.5.0. A license with no subgroup, such as a license issued before Splunk Enterprise 6.5.0, is treated as though its subgroup is Production.


You can define a pool of license volume from a given license license stack and specify other indexing Splunk instances as members of that pool for the purposes of volume usage and tracking.

A license pool is made up of a single license master and zero or more license slave instances of Splunk configured to use licensing volume from a set license or license stack.

License slaves

A license slave is a member of one or more license pools. A license slave's access to license volume is controlled by its license master.

License master

A license master controls one or more license slaves. From the license master, you can define pools, add licensing capacity, and manage license slaves.

Types of Splunk software licenses
Install a license

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters