After you have change that value to indexes.conf splunk start to check if there are buckets which all events are older than this value. If there are then it deletes (move to frozen) them. After that it does it periodically. If you are doing this with GUI splunk manages reboot if needed. If you are directly editing this on FS on individual system then you must reboot or refresh manually.