The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.
The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)
See the following for info on how to query for frozen durations:
The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps)
- on an indexer cluster, check the indexes.confs on the cluster master in