I've seen license-related events in the _introspection index before, so I'm leaning towards that as the answer. But I'll review my notes just to be sure.
I'm a bit unsure about this one. I know there are a few different internal indexes in Splunk, but I can't recall which one specifically handles license data.
Izetta
14 hours agoHester
6 days agoMaryann
11 days agoLenny
16 days agoMarkus
21 days agoTeresita
26 days agoCamellia
1 month agoBenedict
1 month agoMaile
1 month agoDiego
2 months agoAvery
2 months agoRonnie
2 months agoFreeman
2 months agoTijuana
2 months agoMelissa
2 months agoMacy
3 months agoGearldine
3 months agoLawrence
3 months agoAdria
3 months ago