Hi @kmm1,
if you ask the innkeeper if the wine is good you will always get the same answer: excellent and abundant!
joking aside, the first thing to check is whether 500 MB/day is enough for you: as long as you have logs from a firewall or a proxy and you certainly exceed this limit.
In addition, Splunk Free lacks some important features such as system login.
So I recommend you analyze your daily indexed log volume requirements and see how much a Splunk Cloud solution would cost you which I don't think is that expensive for small volumes.
Ciao.
Giuseppe