I've seen license-related events in the _introspection index before, so I'm leaning towards that as the answer. But I'll review my notes just to be sure.
I'm a bit unsure about this one. I know there are a few different internal indexes in Splunk, but I can't recall which one specifically handles license data.
Hui
1 day agoTanesha
6 days agoRonnie
11 days agoAlexia
17 days agoWendell
22 days agoCarin
27 days agoIzetta
2 months agoHester
2 months agoMaryann
2 months agoLenny
2 months agoMarkus
2 months agoTeresita
2 months agoCamellia
3 months agoBenedict
3 months agoMaile
3 months agoDiego
3 months agoAvery
3 months agoRonnie
3 months agoFreeman
4 months agoTijuana
4 months agoMelissa
4 months agoMacy
4 months agoGearldine
4 months agoLawrence
5 months agoAdria
5 months ago