Hi - I am archiving data to the frozen dir using the frozentimeperiodinseconds which works well. I now want to automate the deletion of this data from my frozen dir after a certain period. I have read somewhere this can be done - can someone point me to documentation which would help.
There is no automagical management of the frozen buckets. Once they're frozen... you can thaw them (a manual process) or manage the directory yourself (with a script looking at the file dates). The info provided in the doc about the thawing process will give you the bits you need to understand how the buckets are named, organized etc... but they are no longer touched or managed by Splunk once they're frozen, until you thaw them...
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata