I am currently restructuring our logging architecture and want to move existing cold data to hot data but wanted to ensure this was possible or if anything special was required other than a simple move from one directory to the next.
Thanks!
Check this one: https://answers.splunk.com/answers/208985/how-to-rollback-buckets-from-cold-to-warm.html
View solution in original post