Hello, I am trying to delete data from _audit index. Currently it contains last 6 years data and occupying lot of space. I modified the $SPLUNK_HOME/etc/system/default/indexes.conf and added below under _audit stanza:
[_audit]
FrozenTimePeriodInSecs = 3153600
I restarted the splunk after making the changes. But I still see older data under Audit. Can you please help in finding what is wrong here? Do I need to make any additional changes or invoke anything to reflect the changes?
Thanks in advance for your help.
It might be configured in some other apps. Please check the value through btool.
./splunk btool indexes list _audit --debug | grep frozenTimePeriodInSecs