We've recently realized that we were rolling our buckets out the coldPath too soon - thereby not making full use of the homePath volume which uses directly-attached SSDs. I've increased maxWarmDBCount for most of the indexes and I'd now like to bring the buckets that have already been rolled out to cold back to the faster homePath.
I've reviewed https://answers.splunk.com/answers/208985/how-to-rollback-buckets-from-cold-to-warm.html but it reads like it's intended for a deployment that doesn't have clustered indexers.
Does anyone have a procedure that can be used in a clustered deployment?