We need to do indexer archiving. We have a clustered environment with 4 Search Heads and 4 indexers each. Can anyone suggest if you have ever tried the option of using coldToFrozenScript in the indexes.conf? If yes, let me know what details have to be mentioned there and how can it be used.
I have referred the docs and noticed that the sample script is available for this in the Splunk Enterprise product.But I am not sure of what all parameters need to be added/changed in this script for it to work in our case.We have a linux server hosting splunk in clustered environment.Some simple example would be easier to understand.