Hi,
I'm looking for information how Splunk 7.0 will behave when Non-enforcement enterprise license expires.
Specifically I would like to know if Splunk allows users to keep searching as in the case of acquiring five warnings in a 30 day window.
Splunk will disable searching if license gets expires but keep indexing data. Refer doc for more info: http://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/Aboutlicenseviolations
http://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/TypesofSplunklicenses
There is no information in documents you've mentioned about how Splunk will behave when the non-enforcement license expires. There is only information what happen in case of five warning during 30 days.
Could you tell me how do you know that Splunk disable searching when non-blocking enterprice license espires?