For understand this let read Splunk-6.1.1-Admin manual
p93 (Free License)
P110 (What About Violations and Warnings)
P112 (How To Avoid License Violation and correcting License warning)
NOTE : Search this manual in splunk Documentation
The quick answer is that it is your job to ensure that you don't send too much data to Splunk and go over the free license limit. Splunk will not do it for you, and there is no way to configure it (easily) to make it so that it does.
Part of it might be you doing some regular monitoring, and shutting things off when they get too chatty. Part of it might be reducing the number of your inputs. Part of it might be writing some props/transforms configuration stanzas to reduce the size of the inputs you are taking in. Part of it might be setting up multiple Splunk servers with free licenses and directing your traffic so that none of them goes over. But there is no way to tell Splunk, "Stop indexing at the free license limit."
OK thank you for your answer.
I have reduced the number of logs in the inputs file.
Now i have just 2 servers which send the windows event log to splunk forwarder.
disabled = 1
disabled = 1
disabled = 0
I think that the licence limit will be good now.
And I wait that Splunk unlock the seach task? Or I must change anything else?
Thank you a lot.