Hi, no I never got an answer to this and AFAIK, you are unable to split your license daily usage into pools and then strictly limit those pool to usage limits. As you said you will only get alerted when a certain pool reaches its soft limit. You could setup a script on forwarders in your dev/qa pools to query the splunk api for its usage and when it reaches that daily usage to turn of the its forwarder, but watch out when the forwarder next starts to make sure it does not pick up everything from when it was running last.
Maybe somebody else is doing this in a better way and can comment ???
... View more