Splunk® Light

Installation Manual

Download manual as PDF

This documentation does not apply to the most recent version of SplunkLight. Click here for the latest version.
Download topic as PDF

About Splunk Light licensing

Splunk Light licenses control the indexing volume and feature set of the Splunk Light product. Users can increase the indexing volume capacity on a per-GB basis.

Splunk Light license types

Splunk Light ships with a free license and offers paid license options that you can buy.

License Type Description
Splunk Light Free Included with the Splunk Light download package. This license offers up to 500MB daily indexing volume and a single administrator account.
Splunk Light Perpetual Offers a daily indexing volume capacity up to 20 GB and up to 5 administrator or user accounts.
Splunk Light Term Offers a daily indexing volume capacity up to 20 GB and up to 5 administrator or user accounts. You can renew this license at the end of its subscription term.

Splunk Light features by license type

The following table lists the Splunk Light features enabled by the license type.

Features Splunk Light Free Splunk Light
Daily Indexing Volume Up to 500MB Up to 20GB
Search and Reporting Yes Yes
Dashboards Yes Yes
Alerting No Yes
Accounts 1 Admin Up to 5, Admin and User
Add-ons Yes Yes

Exceeding your license

Warnings and violations occur when you exceed the maximum daily indexing volume allowed for your license.


If you exceed your daily indexing volume on any calendar day, you get a warning. The message persists for fourteen days. You have until midnight to resolve it before it counts against the total number of warnings within the rolling 30-day period.


If you have five or more warnings in a rolling 30-day period, you are in violation of your license. During a license violation period:

  • Splunk Light continues to index your data.
  • Search is disabled, except for searches to the _internal index.

Although you cannot search existing or incoming data inputs, you can still use search to troubleshoot the licensing issue.

Search capabilities return when you have fewer than five warnings in the previous 30 days or when you apply a reset license.

License expiration

When your Splunk Light Term license expires, you can do one of two actions: Update your license or Revert to the Splunk Light Free License.

You cannot convert the instance to a Splunk Forwarder or switch between license groups.

Update your license

Update your license to install a new Splunk Light license or install a Splunk Enterprise license to upgrade to Splunk Enterprise.

When your Splunk Light license expires and you upgrade to Splunk Enterprise, your data, searches, alerts, knowledge objects, and settings should migrate seamlessly. If you have add-ons enabled, they remain active and appear in the Apps browser view of Splunk Enterprise.

See "About migrating Splunk Light" and "Update your Splunk Light license".

Revert to the Splunk Light Free license

When your Splunk Light license expires and you revert your instance to Splunk Light Free, your instance limits to a single account with administrator privileges. Previous settings such as accounts, passwords, and configurations persist, though you cannot modify them in Splunk Light Free. If you upgrade this instance back to Splunk Light (or upgrade to Splunk Enterprise), your previous configurations restore.

To log in after you revert to Splunk Light Free

If you have more than one admin account configured on the Splunk Light instance, after you revert to Splunk Light Free, the login account becomes the admin account that is first in alphabetical order.

To change this, do the following:

1. Stop Splunk Light Free.

2. Back up the original <SPLUNK_HOME>/etc/passwd file.

3. Edit <SPLUNK_HOME>/etc/passwd file to remove all entries except one Admin user.

4. Start Splunk Light Free.

5. Log in using the Admin account you saved.

When you upgrade back to Splunk Light or Splunk Enterprise, remember to restore the passwd file from the original backup.

Install and deploy a universal forwarder
Update your Splunk Light license

This documentation applies to the following versions of Splunk® Light: 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5


Uspinar, your Splunk Light Trial license should automatically revert to a one-year Splunk Light Free license at the end of the 30-day trial period.

Andrewb splunk, Splunker
October 4, 2018

I have downloaded Splunk light trial version and want to switch my license to free from trial. However I do not see that option available under system>licensing
How should I proceed?

October 3, 2018

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters