All indexed data is not stored in 'defaultdb'. It could be that you're indexing data into other indexes. Defaultdb is the 'main' index, where data is sent if you haven't specified any other index. If you've got a custom index, data will be written to that index, and not 'defaultdb' in $SPLUNK_HOME/var/lib/splunk/. You've also got the internal indexes within Splunk, but that data shouldn't be counted by the indexing volume page.
Keep in mind that warm buckets only contain data that is not going to be written to again, so if you're looking at warm buckets that contain data for a specific time period, there could also be hot buckets that are still being written and haven't yet been rolled to warm.
Data is also compressed when it is written to disk, so although you're charged for 300mb, it isn't a 1:1 storage ratio. Usually the figure that is tossed around is ~50%.
It might also be possible for a person to configure index retention in such a way as to clear out data older than a certain period of time/over a certain size. If that is done, you won't be able to tell by the size of the index about the indexing volume for that day.
For these reasons, I wouldn't recommend that you use a method of looking at physical space used on disk to determine how much size is used. The page you're looking at hits the rest endpoint and that counts the totality of indexed data in non-internal indexes from midnight until the time you view the page.
If you think you're having problems, start with this page:
http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume
... View more