In last couple of days, I have seen few license alerts:
This pool has exceeded its configuration poolsize=5GB bytes. A CLE warning has been recorded for all members.
Then I tried to look at the License Usage report by host and I see couple of issues:
1. My indexer itself it using up most of the license.
2. My indexer is listed twice, one in all capitol (SPLUNK-SERVER1) and 2nd one, regular FQDN (splunk-server1.mydomain).
For the 1st issue, checked more and saw /var/log/audit/audit.log is the culprit. What can I do to limit it?
For the 2nd issue, I guess, I have spelled out server name differently. Where can I check other than /opt/splunk/etc/system/local/server.conf?
Thanks for your help.
Check the usage by sourcetype, index... Then check what kind of logs these are. We don't know yohr environment, we don't know your data.