I have indexing data into Splunk. once the Cold bucket time period reached one month the data have to move to the frozen bucket every month. The frozen bucket is available in NAS file system. Could some one help me how to move data from cold bucket path to NAS path.
let me know in this scenario what will help
a. any script need to put ?
b. we can mention directly in index stanza it will move ?
Thanks in Advance.