Sorry for the bad translation.
I have a Cloud client.
The license is 50GB by day
Additional DDAA has been contracted about what is not very clear to me, the shared documentation seems to be outdated or not available.
When I go to "Settings" - "Indexes" I can see the indexes used by this client and the others that are internal to splunk from what I see.
I see that one of the indexes has already reached the maximum size of 500GB and I don't know if it has the DDAA active.
According to this image I understand that the DDAA is active? I must do something?
I am worried if information is being lost since the client needs to retain that data for a long time