Search for AWS runs out of the box with no license key on a capable free tier. A paid license raises the limits and unlocks the multi-account and multi-user features.
Beta. Search for AWS is in beta, and the license comes with the app: when we send the package we send a key for the beta with it, so a beta installation is not held to the free-tier limits while that key is valid. The tiers below are what the app enforces - the free tier is what remains if the key is removed; an expired key keeps working through the 14-day grace period and then stops the commands until it is renewed or removed, as described below; and the paid tier is what a key grants, up to the counts written into it.
Free tier
With no license key configured, the app provides:
- One registered account, with static keys or, on a self-managed EC2 search head, the instance role.
- A single, standalone search head.
- The shared credential model: every user’s searches use the account’s credential.
The free tier never expires. It is enough to evaluate the app and to run it for a single account on a single search head.
Paid
A paid license unlocks:
- Multiple accounts, up to the count in your license.
- Search head clustering - running the app across SHC members.
- Cross-account assume-role credentials (see Accounts).
- Per-user credentials (see Access control).
What happens at the limits
Enforcement is designed to be predictable and never to lose your configuration:
- Registering a second account on the free tier is refused with a clear message, and the Add account button says why. The account you already have keeps working.
- Choosing assume role for an account on the free tier is refused the same way.
- Running in a search head cluster without a paid license blocks the search commands with a message naming the reason; your registrations stay stored.
- An expired paid license keeps working through a 14-day grace period, with a warning on the License tab. After grace, the search commands stop with a message asking you to renew; nothing is deleted, and everything resumes the moment a valid key is entered.
- An invalid or mistyped key counts as no key: the app warns and runs as the free tier until you replace it.
- Falling back to the free tier with a paid setup still in place - a removed key, or a mistyped one - does not grandfather that setup. While more accounts are registered than the tier allows, every search stops with a message that names both numbers; an account that uses assume role is refused on its own, and the others keep working. Remove the extra accounts or switch the credential on the Setup page, or enter a valid key. Nothing is deleted for you.
Enter a license key
Open the Setup page and go to License. Press Add license, paste the key, and save. Line breaks and spaces an email client wrapped into the key are dropped on save. The tab then shows the current status: the license id, the number of accounts and installations it allows, and the expiration date. A key you enter or remove applies from the very next search; a key that expires is noticed within 30 seconds.
To clear a license and return to the free tier, press Remove license. The key is stored in aws_search.conf, is readable only by full Splunk administrators, and is never displayed again after saving. In a search head cluster it replicates to every member; the cluster counts as one installation.
Evaluate
During the beta the license comes with the app: contact sales@outcoldsolutions.com for the package and the key, and paste the key into the License tab as above. Once the app leaves beta, an evaluation license is requested the same way.