I have changed the data retention and pushed the bundle from the cluster master. In 2 indexers, the data got deleted but in one indexer, it's still the same. The indexes.conf in the slave-apps is same on all 3 indexers. What changes do I have to make so that the indexer will remove data from the cold buckets of one index?
run this on cluster master, /opt/splunk/bin/splunk show cluster-bundle-status and validate the bundle status. all indexers should have the same bundle id and time.
keep the cluster master in maintenance mode /opt/splunk/bin/splunk enable maintenance-mode and restart all the indexers. hopefully this will fix the issue. then disable the maintenance mode /opt/splunk/bin/splunk disable maintenance-mode