I am facing a license violation issue,
I have received 4 warnings (29th 30th 31st 1st august) but 2nd and 3rd September there is no violation. But what we are thinking is we don't want to take a risk. To avoid that risk, we are thinking of increasing the license, but before increasing the license, my manager wants justification for why these violations have happened.
So i went to the license usage report and checked for last 30days and in sourcetype "wineventlog:security" consuming more data in Splunk.
Then i compared the logs 26th august (205 gb wineventlog:security) and 31st august (260 gb wineventlog:security) but they want to know why this much of data was used and to know where it came from.
Team can you please help me get this report.
Thanks and regards,
... View more