Refine your search:

3
1

We recently purchased Splunk and upgraded from a Free license to an Enterprise license.
After I installed the new license and restarted some of our indexes did not appear in the UI and our summary page shows a smaller event count.
What happened? All I did was install a new license?

asked 23 Mar '11, 21:26

Ellen's gravatar image

Ellen ♦
1.7k319
accept rate: 72%


One Answer:

The Splunk Free license is a single user product that does not use authentication or access controls. Indexes created with the Free license are not searchable because under the Enterprise license the admin role does not have permission.

To resolve this go to manager>>Access Controls>>Roles>>Admin and add the missing indexes to the "Indexes searched by default" list of selected indexes.

link

answered 23 Mar '11, 21:33

Jaci's gravatar image

Jaci ♦
8722217
accept rate: 75%

edited 23 Mar '11, 21:55

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×299
×127
×44

Asked: 23 Mar '11, 21:26

Seen: 490 times

Last updated: 23 Mar '11, 21:55

Copyright © 2005-2012 Splunk, Inc. All rights reserved.