Splunk Free

noun

A version of Splunk that is free, as in beer! Splunk Free allows you to index up to 500MB/day and will never expire. If you go over 500MB/day more than 3 times in a 30 day period, Splunk will continue to index your data, but search will be disabled until you are back down to 3 or fewer times in the 30 day period. You can switch directly to Splunk Free from the Splunk Enterprise Trial if you like.

For more information

In the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time