Sidehistorik
I am not impressed with the standard Splunk license info, when the filling of my indexes are more that the license allows; so I have build a simple Dashboard to finde in find which index indexes and from what server the filling is commingcoming:
The dashboard shows the introduction of the PacketBeat from Elasticsearch and my Alfresco server (afserver), filling insane amounts into the index.
...