I want to know how to differentiate between logs from a productive versus a non-productive license.
Could you please provide some more details if your focus is more about how to write a splunk search to differ between different stages/environments or licensing in general?
Regarding licensing license pools may be helpful in your case Create or edit a license pool - Splunk Documentation
I know my question is very general, but yes I will like to know, how I can know if the logs come from different environments. and know which one.