We were using a system which has a central Splunk head and multiple search peers where the search peers were DISABLED.
Is it possible that an upgrade to Splunk 5 re-enabled them ?
I went to Splunk Manager -> Licensing -> Enterprise license group and I see that ALL MY SEARCH PEERS AS WELL AS MY SEARCH HEAD are using up daily volume.
I doubt that that is the case (that an upgrade can re-activate configuration), but is it actually possible for something like this to happen ?
if the search was disabled for any license issue, you need a reset key to unlock the search.
If you have a support contract, file a ticket, otherwise, wait for 30 days for the automatic unlock.