License Violations continue daily even though I have taken the daily indexing down below the Allowance. With a 500Mb Enterprise limit, I have managed to decrease the amount of data flowing in daily to >200Mb. Yet I continue to get violations.
I have tried re-applying my license, Changing to a temporary license, rebooting server; even tried to wait out the 7 day period required to refresh system. Each day i receive a new violation. Right now I'm sitting on violation #21 and there isn't any problem searching.
Should I completely disable all inputs and let it go on for 7 days collecting nothing or is there a better way of making this stop? What would make Splunk get caught in this loop of thinking there are violations when there are not?
... View more