Hello,
I configured my index in the /etc/system/local/indexes.conf as follows:
[weblogsindex]
homePath = $SPLUNK_DB\weblogsindex\db
coldPath = $SPLUNK_DB\weblogsindex\colddb
thawedPath = $SPLUNK_DB\weblogsindex\thaweddb
frozenTimePeriodInSecs = 47304000
However I don't see any buckets being deleted from the folder, and the disk usage is still increasing.
How can i check what the youngest event in a bucket is, or is there a better way to see if the archiving is working, that would be much appriciated.
If I may ask a silly question or two - have you confirmed you have data that's older than 1.5 years in that index?
If it's disk space you are trying to control and not actual age of events, perhaps maxTotalDataSizeMB
might be a more useful setting? You can find it, as with all other indexes.conf setting, in the documentation:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf
I know that's not an answer to your question, but it might be an answer to your question. 🙂
Also, read carefully the description of frozenTimePeriodInSecs - all the data in the bucket must be older than that age before it'll delete it. By that, I just mean that if you are close - like your oldest data is from 100 days ago and you had frozenTimePeriodInSecs set to 8640000, .... I'd not be worried until you hit at least another few days before it deleted. Is it possible this is the problem?