Dears, I am using Splunk 6.4 as a heavy forwarder which send its logs to an indexer (6.3) .
Heavy forwarder has MySQL add-on installed on it. While trying to search indexed data, I got the error below that my license expired or has been violated, despite still having not indexed any data or expiration date hasn't come!
Remember that licenses are not ONLY about how much data you index per day. The Enterprise license also conveys capabilities, such as distributed search. That's why you need to follow @somesoni2's suggestion.