Is there a way I can keep track of the 500MB limit on the Free Splunk to where I can stop Indexing when I get close to 500MB?
I'd love to see an answer as well, since I'm running the same at home.
The hack I have so far is this, which is probably wrong:
index=_internal source="/opt/splunk/var/log/splunk/license_usage.log"
| stats sum(b) AS bSum first(poolsz) AS poolSz by idx
I imagine you can set up an alert when bSum is close to poolSz?