I'm using the forwarder license on my search head. I've disabled all inputs, and any extra apps. Yet I still get license violations. 7.1MB was indexed yesterday, for example.
What's the magic to make this stop happening?
Splunk 4.1.4 x64 on SuSE Linux.
Hi, maybe you can run
>splunk list monitor
on search head, to get all active monitored inputs
Do you happen to have any summary indexes?
I had the same issue where I had a summary index that wasn't named "summary", and it counted against my license..
I ended up setting up my search head as a forwarder to my two indexers and it seemed to resolve the issue.
Brian
Hi, maybe you can run
>splunk list monitor
on search head, to get all active monitored inputs