I modified $SPLUNK_HOME/etc/system/local/indexes.conf for the specific index to keep only 10 warm databases; however, it is not working as I have over 160 warm databases in my local disk under the "db" directory.
Is this the incorrect file?
Configuration as follows:
coldPath = /mnt/splunk_data/serverlogs_01/colddb
homePath = /splunk_data/serverlogs/db
thawedPath = /mnt/splunk_data/serverlogs_01/thaweddb
maxWarmDBCount = 10
Does Splunk have permissions or any problems writing to the coldPath? Also, are there any indications in splunkd.log of any problems (or successes) rolling the warm buckets?
Yes; several times.
The changes were made several restarts ago.
Any other ideas?
did you restart the server once you changed the configuration?