LICENSEWARE

Splunk Enterprise license management

This article is about how Splunk Enterprise licences are measured, installed and allocated on premises (license manager, stacks, pools, components, licence types). The warning and violation thresholds are covered in Splunk licensing under Cisco. It is not legal advice and does not replace the Order.

On This Page

Splunk Enterprise is Splunk’s self-managed data platform, deployed on premises, in a private cloud or in air-gapped environments. A commercial Splunk Enterprise licence is bought either as a volume licence measured in Daily Indexing Volume or as an infrastructure licence measured in vCPUs; the two cannot be stacked together, and premium apps must use the same licence type as the core licence.[7] Both licence types give access to the full feature set and to single-instance or distributed installations.[2] This article describes how usage is measured and how licences are organised in a deployment; Splunk’s warning and violation thresholds (search blocking for stacks under 100 GB a day, the 72-hour license peer rule, the no-enforcement key) are covered in Splunk licensing under Cisco.

Editions

Splunk Enterprise has no feature editions; the licence type decides capacity and enforcement. The documented licence types are:[2]

Licence Capacity Stacking Notes 
Enterprise, volume-based Daily Indexing Volume in the Order Stacks with other volume licences, not with vCPU Blocks search after a set number of warnings when the stack is under 100 GB/day 
Enterprise, infrastructure vCPUs in the Order Stacks with other vCPU licences Logs warnings and messages; search not blocked 
Enterprise Trial 500 MB/day for 60 days No Generated on install; standalone single instance only (rule) 
Free 500 MB/day, no expiry No Single instance; no users, roles, alerting, distributed search or clustering 
Dev/Test Volume per the customer Order No Requires a paid licence; replaces other licence files when installed 
Personalized Dev/Test 50 GB/day, 6 months renewable No Individual, non-commercial testing by employees of paying customers 
Developer 10 GB/day, 6 months renewable No Under the Splunk Developer Agreement, for building content (rule) 
Build Partner 50 GB NFR n/a For Splunk Build Program partners 
Forwarder No indexing No For instances that only forward data 

The Free licence lets a user bulk-load a larger data set up to two times within 30 days, and disables search after three warnings in a rolling 30-day window.[6] The Personalized Dev/Test license is available to Splunk Enterprise and Splunk Cloud customers, is limited to standalone non-production use, and a company may hold several such individual licences at a time.[10]

Splunk also sells limited-scope Splunk Enterprise licences. Rapid Adoption Packages are measured by the number of Use Cases in the Order but capped at 25 GB/day, a single instance and no stacking with other licences; the Use Cases belong to packages such as Storage, Network, Server, Application and Web Management and Basic Security Monitoring.[7][12] Splunk Enterprise for DNS and Netflow Data counts only listed source types (any source type containing “dns”, “netflow”, “sflow” or “jflow”, Zeek, Corelight, AWS VPC flow logs and others) and may be combined with other volume licences, while Splunk Enterprise for Cisco AnyConnect NVM is sold per endpoint at 10 MB/day each.[7]

Metrics

Daily Indexing Volume

Volume is measured during indexing and reported to the license manager. The measured volume is “based on the raw data that is placed into the indexing pipeline”, not the compressed size on disk, so data filtered and dropped before indexing does not count.[1] The Purchase Capacity page defines Daily Indexing Volume as “the daily aggregate volume of uncompressed data for indexing as set forth in the Order”.[7] The day runs from midnight to midnight on the license manager’s system clock.[1]

Not counted against the quota (rule):[1]

  • Splunk’s own logs in internal indexes such as _internal and _introspection.
  • Summary indexing and metric rollup summaries.
  • Data removed before indexing, including data that ingest actions filter or route away so that it never reaches an index.[8]
  • Replicated copies in an indexer cluster: “Only incoming data counts against the license; replicated data does not.”[3]

Metrics data uses the same quota as events, but each metric event is measured at its size plus 18 bytes, capped at 150 bytes (rule).[1]

vCPU

For infrastructure licences a vCPU is any logical CPU core as reported by the host operating system: a physical core, a hyper-threaded or simultaneous-multithreading logical core, or a shared virtual CPU. The total vCPU count across all Splunk Enterprise search heads and indexers counts towards the licensed capacity (rule), and Splunk points to the Monitoring Console’s CPU usage dashboards, filtered to the search head and indexer roles, to check the count.[1] Splunk’s comparison table shows infrastructure licences logging warnings and displaying messages but not blocking search.[2]

Counting / floors

Groups, stacks and pools

Licences are held on a license manager, a Splunk Enterprise component that groups licences into stacks, divides stacks into pools and assigns license peers (indexers, search heads, heavy forwarders) to a pool.[4]

  • Groups. Only one licence group is active on a license manager: Enterprise/Sales Trial, Enterprise Trial (the default on a new install, which cannot be returned to once left), Free, or Forwarder.
  • Subgroups such as DevTest and Production are set inside the licence file; a licence belongs to one subgroup.
  • Stacks. Enterprise and Sales Trial licences stack, so added capacity is installed alongside existing licences. Daily volume is tracked, and warnings raised, at stack or pool level.
  • Pools hold part or all of a stack’s volume, so that, for example, test indexers draw from a different pool than production indexers.

Stacks and pools are not available for Enterprise Trial, Free, Dev/Test or Forwarder licences, and installing a Dev/Test licence over an Enterprise licence deletes the Enterprise licence (rule).[4] When the first Enterprise licence is installed, the instance becomes the license manager, with a default stack called “Splunk Enterprise Stack” and a default pool, auto_generated_pool_enterprise, open to every license peer.[5] A pool can be opened to any license peer or limited to named indexers.[5]

Components that need a licence

Every Splunk software instance needs a licence. Indexers, search heads, the deployment server, the indexer cluster manager node, the search head cluster deployer and the monitoring console all need access to an Enterprise licence, even when they index no external data. Universal and light forwarders need only the Forwarder licence; a heavy forwarder that indexes data or uses other Enterprise features must connect to the license manager. Because data is metered only when indexed, forwarders incur no licence usage (rule). All nodes of an indexer cluster must share the same licensing configuration.[3]

Cisco data weighting

Under Integrated Enterprise Value, eligible Cisco-generated data ingested with a supported, unrenamed sourcetype counts at a 0.5x weighted rate (20 GB/day counts as 10 GB/day). For Splunk Enterprise the benefit applies only to ingest licences above 100 GB/day; it does not change vCPU or other workload consumption (rule), and it does not reduce the physical data volume that must be sized.[9] Splunk says Monitoring Console reporting of weighted consumption is “coming soon”, and until then customers should ask their account team for the IEV-weighted figures.[9]

Verification

The license manager’s usage report is not the only check. Under the Splunk General Terms Splunk may ask, at most once every 12 months, to verify usage of on-premises products against the Capacity, and may invoice any excess at the list price then in effect (rule).[13]

Virtualization & partitioning

There is no sub-capacity or partitioning rule for vCPU licences beyond the operating-system count: a vCPU is whatever the guest operating system reports, including hyper-threads and shared virtual CPUs, and every search head and indexer counts.[1] The Purchase Capacity page equates each vCPU with “a distinct hardware thread of execution in a physical CPU core”.[7] Volume licences are indifferent to virtualisation because they measure data, not hardware.

Cloud / BYOL

Splunk Enterprise may run on customer-designated hardware, including infrastructure operated by a third party for the customer; verification then extends to that hosted installation.[13] Moving to Splunk Cloud Platform requires a Splunk Cloud subscription; see Splunk Cloud Platform subscriptions.

Programs

Splunk Enterprise term licences come with a Success Plan and support under the Support Policy, which supports each Splunk Enterprise minor version for 24 months from release (for example 10.4, released 2026-05-18, until 2028-05-18) and each Universal Forwarder minor version for 60 months.[11] Odd-numbered 10.x releases such as 10.1, 10.3 and 10.5 are listed as “Not Released” for Splunk Enterprise.[11]

Out of scope

Licence warnings, violations and enforcement keys are covered in Splunk licensing under Cisco. Premium apps (Enterprise Security, ITSI) are covered in Splunk Enterprise Security and ITSI licensing.

References

  1. How Splunk Enterprise licensing works (Splunk Enterprise 10.4)Page metadata last updated 2026-06-16. Catalog: How Splunk Enterprise licensing works (Splunk Enterprise 10.4)Effective 2026-06-16. Retrieved 2026-10-02.
  2. Types of Splunk Enterprise licenses (Splunk Enterprise 10.4)Page metadata last updated 2026-05-17. Catalog: Types of Splunk Enterprise licenses (Splunk Enterprise 10.4)Effective 2026-05-17. Retrieved 2026-10-02.
  3. Licenses and distributed deployments (Splunk Enterprise 10.4)Page metadata last updated 2026-05-17. Catalog: Licenses and distributed deployments (Splunk Enterprise 10.4)Effective 2026-05-17. Retrieved 2026-10-02.
  4. Allocate license volume (Splunk Enterprise 10.4)Page metadata last updated 2026-06-16. Catalog: Allocate license volume (Splunk Enterprise 10.4)Effective 2026-06-16. Retrieved 2026-10-02.
  5. Create or edit a license pool (Splunk Enterprise 10.4)Page metadata last updated 2026-05-17.Effective 2026-05-17. Retrieved 2026-10-02.
  6. About Splunk Free (Splunk Enterprise 10.4)Page metadata last updated 2026-05-17.Effective 2026-05-17. Retrieved 2026-10-02.
  7. Splunk Offerings Purchase Capacity and LimitationsLast updated September 2026 (no day stated). Catalog: Splunk Offerings Purchase Capacity and LimitationsRetrieved 2026-10-02.
  8. License implications (Ingest Actions)Page metadata last updated 2026-02-18. Catalog: License implications (Ingest Actions)Effective 2026-02-18. Retrieved 2026-10-02.
  9. Integrated Enterprise Value for Cisco data (Splunk Enterprise 10.6)Page metadata last updated 2026-09-09. Catalog: Integrated Enterprise Value for Cisco data (Splunk Enterprise 10.6)Effective 2026-09-09. Retrieved 2026-10-02.
  10. Personalized Dev/Test Licenses for Splunk CustomersNot date-stamped.Retrieved 2026-10-02.
  11. Splunk Support PolicyLast Updated: August 2026. Catalog: Splunk Support PolicyRetrieved 2026-10-02.
  12. Use Case definitions (Splunk Enterprise Rapid Adoption Packages)Not date-stamped. Catalog: Use Case definitions (Splunk Enterprise Rapid Adoption Packages)Retrieved 2026-10-02.
  13. Splunk General TermsLast Updated: May 2026. Catalog: Splunk General TermsRetrieved 2026-10-02.

See also

Catalog Rows Cited

3Metrics10Rules2Programs

Esc