All Apps and Add-ons

License used but no corresponding events in index


The license_usage.log on my license master indicates usage for the sourcetype MSExchange:2013:MailboxAudit but no events are returned in searches.

alt text

alt text

I've run the above searches using all time real time to rule out time discrepancies and license usage with no events for that time period are still present. My role has privileges to view this data.
This question appears to be a very similar situation. I am unable to simply disable this input to resolve this. Can anyone explain what is going on?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!