In Splunk Cloud if we run out of storage with daily ingestion in DDAS, the storage automatically gets expanded and we are charged for the additional DDAS units at the end of each quarter we are above our licensed DDAS limit. What are some best practices to keep the DDAS limits in check & prevent from exceeding the subscribed limit?
It all comes down to reducing the amount of data stored. Ingest less data and/or allow indexed data to expire sooner.