Migrate to the new Splunk Enterprise licenser
Learn how to migrate your license configuration from a Splunk Enterprise deployment that runs a version earlier than 4.2 to the 4.2 and later licenser model by following the procedures in this topic.
Note: This topic does not cover the upgrade of an entire Splunk Enterprise deployment. See How to upgrade Splunk before you upgrade your Splunk Enterprise deployment.
Before you proceed, see the following:
- How Splunk licensing works in the Admin Manual for an introduction to Splunk licensing.
- Groups, stacks, pools, and other terminology in the Admin Manual for more information about Splunk license terms.
Migrating from an older version of Splunk Enterprise most likely puts you in one of these two categories:
- If you run Splunk Enterprise 4.0 or later, your license will work in 4.2 and later.
- If you migrate from a version of Splunk Enterprise that is older than 4.0, you must contact your Splunk Sales representative and arrange for a new license. See What to expect when upgrading to 4.0 before proceeding with the migration. Depending on how old your version of Splunk Enterprise is, you might want to migrate in multiple steps (for example, first to 4.0, then 4.1, 4.2, and finally 5.0+) to maintain your configurations.
Migrating search heads
If your search heads used old forwarder licenses, they will be automatically converted to be in the Download-trial group. Before you proceed, add your search heads to an established Enterprise license pool. Even if they have no indexing volume, this practice enables Enterprise features, especially alerting and authentication.
Migrate a standalone instance
If you've got a single 4.1.x Splunk Enterprise indexer and it has a single license installed on it, you can just proceed as normal with your upgrade. See How to upgrade Splunk for instructions, and be sure to read the "READ THIS FIRST" documentation prior to migrating.
Your existing license will work with the new licenser, and will show up as a valid stack, with the indexer as a member of the default pool.
Migrate a distributed indexing deployment
If you've got multiple 4.1.x indexers, each with their own licenses, follow these high-level steps in this order to migrate the deployment:
- Designate one of your Splunk Enterprise instances as the license master. A search head is a good choice if one is available.
- Install or upgrade the Splunk Enterprise instance you have chosen to be the license master, following the standard instructions in this manual.
- Configure the license master to accept connections from the indexers as desired.
- Upgrade each indexer one at a time, following these steps:
- Upgrade an indexer to 5.0 following the instructions in this manual. It will operate as a stand-alone license master until you perform the following steps.
- Make a copy of the indexer Enterprise license file. You can locate license files for 4.2 and earlier in
$SPLUNK_HOME/etc/splunk.licenseon each indexer.)
- install the license onto the license master, adding it to the stack and pool to which you want to add the indexer.
- Configure the indexer as a license slave and point it at the license master.
- On the license master, confirm that the license slave connects as expected by navigating to Manager > Licensing and looking at the list of indexers associated with the appropriate pool.
- Once you confirm that the license slave connects as expected, proceed to upgrade the next indexer, following the same steps.
If you have deployed light forwarders, review the information in Migrate from a light forwarder in the Universal Forwarder Manual. You can upgrade your existing light forwarders to the universal forwarder as the universal forwarder includes its own license.
If you have deployed a heavy forwarder (a full instance of Splunk that performs indexing before forwarding to another Splunk Enterprise instance), you can treat it like an indexer--add it to a license pool along with the other indexers.
Migrate a Splunk Enterprise instance
Uninstall Splunk Enterprise
This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0