Licensing for Splunk Enterprise Security
Licensing terms and capacity usage for Splunk Enterprise Security
Splunk Enterprise Security is a premium app, which is used in conjunction with Splunk Enterprise or Splunk Cloud Platform. This means that you must have Splunk Enterprise or Splunk Cloud Platform along with a Daily Indexing Volume or vCPU usage license to download the app from the Splunk Support portal.
For example, if you purchase a 1 GB Daily Indexing Volume license for Splunk Enterprise and purchase Splunk Enterprise Security app, you can only ingest 1 GB of data to use in Splunk Enterprise and Enterprise Security. You do not receive any additional ingestion capacity. However, you are entitled to use Splunk Enterprise Security on your ingested data.
Contact your Sales representative to get pricing details based on your specific workload. Splunk Enterprise Security monitors Splunk indexes for Daily Indexing Volume and vCPU consumption, irrespective of whether you are using the on-prem or the cloud version.
Splunk monitors daily indexing volume into Splunk and the use of that data for security use cases. Splunk also monitors the vCPU usage based on the data summarized in Splunk Enterprise Security specific summary and metrics indexes. For more information, see Use Summary indexing for increased search efficiency.
License usage is measured on Daily Indexing Volume for data sources, vCPUs, and SVC. For more information, see Splunk Offerings Purchase Capacity and Limitations.
To calculate capacity consumption for ingest-based licenses for premium apps such as Splunk Enterprise Security, use the Splunk App for Chargeback.
Trial license to evaluate SPlunk Enterprise Security
To evaluate Splunk Enterprise Security before purchasing, your Splunk sales representative can issue a trial license.
- ES Essentials trial: 30-day term.
- ES Premier trial: 90-day term.
During the trial period, Splunk Enterprise Security displays the trial edition and expiration date in the product's user interface. When fewer than 30 days remain for the trial license to expire, a non-dismissbile warning banner appears that indicates the remaining days for the trial.
If you are an existing ES Essentials customer who is using the trial license for ES Premier, your environment automatically reverts to your purchased ES Essentials entitlement at the end of the ES Premier trial, with no loss of access to ES Essentials features or previously processed data.
When a trial license expires, a permanent non-dismissible banner is displayed across all pages, and access to Mission Control, the Detection Editor, and Content Management is blocked. For ES Premier trials, UEBA access is also blocked.
When running in a search head cluster topology, the trial expiration date and the expiring soon warning banners are not available in the ES UI. Only the expired state is enforced. On Splunk Core version 10.2 and higher, the expiration information becomes available after a search head restart.
When using cloud-connected features with an ES Premier trial license, Splunk Cloud Services does not recognize trial license entitlements. Cloud connectivity and cloud-connected features continue to function during the trial period. However, the entitlement shown in the UI reflects ES Essentials rather than ES Premier. When a paid license is applied after trial, the correct entitlement tier is reflected within a few minutes.
Additionally, you can also apply a new license to your trial, if you upgrade the trial license to a paid license from Splunk at any time to avoid the conclusion of the trial period.