I have installed the splunk deployment monitor app to attempt to pull some stats on what our license usage patterns are.
One issue I see right off the bat is that in 'Licence Report' -> 'Daily License Usage for Last 60 Days' -> Ordered 'by License Pool' it tells me we indexed 130GB which is ok, however this is above our license limit of 120GB yet I don't have any license warnings and other searches I have subsequently made myself show different values.
Is the used search including non licensed data usage such as for the internal indexes?