I've seen license-related events in the _introspection index before, so I'm leaning towards that as the answer. But I'll review my notes just to be sure.
I'm a bit unsure about this one. I know there are a few different internal indexes in Splunk, but I can't recall which one specifically handles license data.
Hui
2 months agoTanesha
2 months agoRonnie
2 months agoAlexia
2 months agoWendell
2 months agoCarin
2 months agoIzetta
3 months agoHester
3 months agoMaryann
3 months agoLenny
4 months agoMarkus
4 months agoTeresita
4 months agoCamellia
4 months agoBenedict
4 months agoMaile
4 months agoDiego
5 months agoAvery
5 months agoRonnie
5 months agoFreeman
5 months agoTijuana
5 months agoMelissa
5 months agoMacy
6 months agoGearldine
6 months agoLawrence
6 months agoAdria
6 months agoJohana
20 days agoBrett
26 days agoNatalya
1 month agoBarney
1 month agoKerry
1 month ago