Paula - there is no published way of resetting your license counter to my knowledge. If you get limits exceeded the requisite number of times in a month then you probably know(?) what happens to your indexing etc? If you are working at those levels then you are clearly not on the free versions, so probably have an enterprise license. Call Splunk or your 3rd party.
You still need to resolve where your issues are coming from - Splunk doesn't arbitrarily continue the volume count, it cycles over each midnight local time.
Run some searches in the 'Search Splunk Answers' for your specifics. I found the following:
index=_internal sourcetype=splunkd source=metrics "group=per_sourcetype_thruput" NOT series="filetrackercrclog" NOT series="splunk*" NOT series="audittrail" NOT series="scheduler" NOT series="searches" NOT series="stash" | eval events=eps*kb/kbps | stats sum(events) as events sum(kb) as kb by series | eval events=round(events,0) | eval kb=round(kb,1)
from Lowell posted way back, so credits to them...
and even hand crafting building on from index="_internal" | timechart sum(kb) by series might give you an insight.
Good luck & BR
D
... View more