Hey hokie1999! The XML files are basically specifying ways to visualize the data Splunk automatically generates about license data. Use these charts and graphs to be able to associate logging spikes with specific systems and sources. It is a 24-hour graph because license violations are on a 24 hour basis. They are simple searches, though, and you can easily customize them to whatever timespan you'd like.