Hi @Afik_Office
Yes it total combining all inputs, if you do not have any messages as license_warning thats good. If you are able to check _internal logs.
index=_internal source=/opt/splunk/var/log/splunk/license_usage.log st=<replace_with_your_sourcetype>
| stats sum(b) as total_bytes
| eval MB=(total_bytes/1024)/1024
--
An upvote would be appreciated if it helps!
Hi @Afik_Office
These are the points to check when you are using free license,
You might be receiving the data on Splunk and indexing it, if you have violated license you are unable to search it hence you are assuming udp stream has stopped receiving. Refer - About license violations - Splunk Documentation
If you want to test its functionality/dev upgrade to dev license which has no restriction but strictly it can not be used for general purpose commercial use - https://dev.splunk.com/enterprise/dev_license
06-28-2021 09:49:52.996 +1000 INFO Metrics - group=per_sourcetype_thruput, series="splunkd", kbps=0.4629412718777596, eps=0.516150377573679, kb=14.3505859375, ev=16, avg_age=0.1875, max_age=3
----
An upvote would be appreciated and accept solution if it helps!