I just decided to try out the free 30-day Enterprise license and after I restart Splunk it says I have exceeded my 5GB/day limit...however this system would be nowhere near 5GB of log data and when I go to the Admin interface and click on "Indexes" and total up the index sizes it doesn't exceed 500MB.
I don't understand how the 5GB/day limit would ever be hit or how Splunk would interpret it to be... Any info would be appreciated.
Thanks.