I'm facing a license issue I cannot understand, althought I read quite a bit about it.
Can anyone help, please, in order to get my splunk cluster in working condition ?
you shared the situation of the last day, but what's the situation of the previous 30 days?
In the first screenshot, there's a message of 9 quota exceeding, this means that there was 9 quota exceedings in the last 30 days and over 5 it's a license violation.
Anyway, Splunk doesn't stop to index and to search, there's only a message.
What, exactly, are you trying to understand?