Is federated search able to search frozen buckets in s3? Or only raw logs?
Splunk is unable to search frozen buckets in any location. Frozen buckets must be thawed before they can be searched.
As I understand it, FS-S3 is intended to allow searching of raw data resident in an S3 bucket. It's not for searching "cooked" data.