I have buckets with hidden (deleted) events that are frozen. I want to thaw these buckets. Will I need to re-delete these events?
Hi,
You will have to specify a setting to archive data from frozen, else Splunk will delete all the data.
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Setaretirementandarchivingpolicy#Archive_d...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Automatearchiving
Let me know if this helps.
The OP already has frozen data.