I received a licensing alert from our one indexer last night (2GB trial license) - I've disabled our noisiest event source and will work to reduce the amount of data being indexed. Is there anything else I need to do to correct this error? Am I going to continue seeing the license warning banner for 30 days?
You'll see the error until you restart splunk, presuming it is the blue error in the top of UI. The license violation will be recorded in your license statistics, and will stay there permanently, however, the product will not be affected until you go over 5 violations within a 30 day period. At that point, searching will be disabled.
If you look at the link below under 'Set up a scheduled search to alert you if a license violation occurs'.
http://www.splunk.com/wiki/Community:TroubleshootingIndexedDataVolume