@ tekwalk.blogspot.com [28-December-2011]
http://tekwalk.blogspot.com/2011/12/is-splunk-eating-up-your-disk-space.html
you can keep a check over that by lowering down its upper-limit over database indices size from several 100s 0f 1000s MBs ((default maxTotalDataSizeMB per index is 500Gigabytes)) to the desired/affordable Size in MBs.
File: /var/ebs/splunk/etc/system/local/indexes.conf
maxTotalDataSizeMB = 3000