I have a trial license on Splunk 6.1.1. I added a new data source today and went over the trial license quota.
Now the number of events indexed is not going up and any searches I do aren't returning any NEW events.
I've read over the relevant sections of the manual and the other questions about licensing here and this doesn't seem to be expected behavior. This is the first license warning we've had.
Glad to hear you got it working. I don't recall ever seeing an index go bad without errors.
Thanks for the pointer. You were correct; it was NOT license related , that was just a coincidence. Something (not sure what) is wrong with the index I was using. Pointing my inputs to the main index resolved the issue.
Are you seeing any errors in the splunkd.log?
It sounds like either your forwarder went off line, or some other failure occured. The problem you're having is not related to licensing.