I'm planning to export and data out of Splunk, anonymize it and import it back. The idea is to use export/import command or event exporttool/importtool
Do those commands count against the license usage?
Export will not be recorded as licence usage, but the act of re-importing will - as far as Splunk is aware you are indexing new data. If that were not the case it would be a trivial exercise to circumvent the licencing altogether by simply scripting regular imports instead of monitoring and indexing live files.