Splunk® Enterprise

Admin Manual

Download manual as PDF

Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
Download topic as PDF

Licenses and distributed deployments

This topic does not pertain to standalone Splunk Enterprise deployments, which consist of a single Splunk Enterprise instance plus forwarders. For a standalone deployment, simply install the appropriate license directly on the instance.

Distributed Splunk Enterprise deployments consist of multiple Splunk Enterprise instances. Separate instances perform various functions such as indexing and search management. Each instance is categorized as one or more component types, based on the functions that it performs. In most cases, an instance serves as just a single component, but it is possible for an instance sometimes to combine the functionality of several components.

See Scale your deployment with Splunk Enterprise components and Components that help to manage your deployment in Distributed Deployment.

This topic discusses the license requirements for each component type. For more information on the types of licenses discussed in this topic, see Types of Splunk software licenses.

License requirements

In a distributed deployment, most Splunk Enterprise instances need access to an Enterprise license:

  • Instances need access to an Enterprise license unless they are functioning only as forwarders. They need this access even if they will not be indexing external data, because the defining features of a distributed deployment, such as distributed search, are available only with Enterprise licenses. For information on the set of features that require an Enterprise license, see About Splunk Free.
  • Forwarders need only a Forwarder license, as long as they are functioning solely as forwarders. If they are also performing functions such as indexing data or managing searches, they need access to an Enterprise license.

The recommended way to give instances access to an Enterprise license is to make them slaves of a license master.

This table provides a summary of the license needs for the various Splunk Enterprise component types.

Component type License type Notes
Indexer Enterprise
Search head Enterprise
Deployment server Enterprise
Indexer cluster master node Enterprise
Search head cluster deployer Enterprise
Monitoring console Enterprise
Universal forwarder Forwarder
Light forwarder Forwarder
Heavy forwarder Enterprise or Forwarder Heavy forwarders that index data need access to an Enterprise license instead of a Forwarder license.

Components and licensing issues


Indexers index, store, and search external data.

To participate in a distributed deployment, indexers need access to an Enterprise license. The data that indexers ingest is metered against the license.

Search heads

A search head is a Splunk Enterprise instance that manages searches.

Search heads need access to an Enterprise license.


Forwarders ingest data and forward that data to another forwarder or an indexer. Because data is not metered until it is indexed, forwarders do not incur license usage.

In most distributed deployments, forwarders only need a Forwarder license. See Forwarder license.

There are several types of forwarders:

  • The universal forwarder has the Forwarder license applied automatically.
  • The light forwarder must be changed manually to another license type. You can use the Forwarder license, but you must manually enable it by changing to the Forwarder license group.
  • The heavy forwarder must be changed manually to another license type. If the heavy forwarder will be performing indexing or using other Enterprise features, it should be made a license slave to a license master node.

A forwarder can use the Free license instead of a Forwarder license, but some critical functionality is unavailable with a Free license. In particular, a forwarder using a Free license cannot be a deployment client and it cannot make use of authentication.

Management components

Management components include the deployment server, the indexer cluster master node, the search head cluster deployer, and the monitoring console. For information on management components, see Components that help to manage your deployment.

All Splunk Enterprise instances functioning as management components need access to an Enterprise license.

Clustered deployments and licensing issues

Indexer cluster nodes

An indexer cluster is a group of indexers that replicate data to promote high availability and disaster recovery. Besides indexers, referred to as "peer nodes" in this context, indexer clusters include other node types; specifically, a master node and one or more search head nodes.

Each indexer cluster node requires an Enterprise license. There are a few license issues that are specific to indexer clusters:

  • Cluster nodes must all share the same licensing configuration.
  • Only incoming data counts against the license; replicated data does not.

Search head cluster members

A search head cluster is a group of search heads that coordinate their activities. Each search head in a search head cluster is referred to as a member.

Each search head cluster member needs access to an Enterprise license.

The search head cluster deployer, which distributes apps to the members, also needs access to an Enterprise license.

Last modified on 06 March, 2020
Types of Splunk software licenses
Allocate license volume

This documentation applies to the following versions of Splunk® Enterprise: 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters