Let's suppose that my free splunk server will receive more that 500MB/day of syslog messages (through the TCP data input). What will happen with the data exceeding the 500MB/day ?
If you exceed your free license 4 times in a 20 day rolling window, your instance will continue to index, but you will not be able to search your data until you change your license.