@x05311,
Check your license usage, which is something you'll want to keep an eye on with only 500MB/day. You can do this by going to Settings > Licensing > Usage Report. Check current and previous 30 days. If you've gone over your license 3 times in 1 month, you'll be unable to search until the next month.
Splunk will continue ingesting data, but you won't be able to search it. Search capabilities return when you have fewer than 5 (Enterprise) or 3 (Free) warnings in the previous 30 days, or when you apply a temporary reset license (available for Enterprise only). If you ARE going over your license, you'll need to decrease inputs so that you're not in violation for 30 days.
https://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Aboutlicenseviolations
... View more