Splunk Free is a totally free (as in beer) version of Splunk. It allows you to index up to 500MB/day and will never expire. If you go over 500MB/day more than 3 times in a 30 day period, Splunk will continue to index your data, but search will be disabled until you are back down to 3 or fewer times in the 30 day period.
Splunk Free is designed for personal, ad-hoc search and visualization of IT data. You can use Splunk Free for ongoing indexing of small volumes (<500MB/day) of data. Additionally, you can use it for short-term bulk-loading and analysis of larger data sets--Splunk Free allows you to bulk-load much larger data sets up to 3 times within a 30 day period. This can be useful for forensic review of large data sets.
Splunk Free is a single-user product. All of Splunk's features are supported with the exception of:
When you first download and install Splunk, you are automatically using an Enterprise Trial license. You can continue to use the Enterprise Trial License until it expires, or switch to the Free license right away, depending on your requirements.
Splunk Enterprise Trial gives you access to a number of features that are not available in Splunk Free. When you switch, be aware of the following:
When you attempt to make any of the above configurations in Manager while using an Enterprise Trial, you will be warned about the above limitations in a Free Splunk.
If you currently have Splunk Enterprise (trial or not), you can either wait for your Enterprise License to expire, or switch to a Free License at any time. To switch to a Free License:
1. Log in to Splunk Web as a user with admin privileges and navigate to Manager > License.
2. Review the text below the License and usage area, find the switch to a free license link, and click it. A login page is displayed.
3. Select Switch to Free License and click Continue.
4. You are prompted to reboot.
Categories: V:4.0.5 | Free license | License | V:4.0.6 | V:4.1beta | V:4.0.7