I have created a c# application(Windows Service) using Splunk SDK C# to monitor splunk licence.
if the indexed data exceeds the value you enter it will disable all UDP inputs and enable them after midnight
The link to the application is down below fell free to change it to your needs.
http://www.codeproject.com/Tips/1112026/Automate-Splunk-Licence-Monitoring
... View more
I have created this simple windows service to monitor and send log events to splunk indexer along with the files copied ,the ip address of the user and the username(json format) it will only send an event if the user copies something.
this is the link to the applications
http://www.codeproject.com/Tips/1109707/Log-USB-Events-to-Splunk-Or-Any-syslog-Server
... View more