About a week ago, daily usage jumped SIGNIFICANTLY. I was no where near the license capacity, now i'm exceeding it and I'm not sure what is generating it.
What can I do to find out what is generating most of the output.
Got to Settings-System-Licensing. Click on Usage Report button,select Previous 30 days tab and from the Split by tab Split by Host from the dropdown. This may show the offending host if its not lumped in with "Other".
There's also the SoS app to look at for current indexing throughput, or the new-in-6.2 distributed management console that has the same info in a prettier wrapping. License Usage Report will be easiest though because it's built-in.
Martin Mueller also recently posted a nice solution that may help you too. See:
http://answers.splunk.com/answers/183473/how-to-find-the-daily-average-of-indexed-data-by-h.html