Hi
I understand there are four buckets in which datas are rolled out in splunk before deleting - Hot,Warm,Cold and Frozen
In the document it is said - to delete the data by maximum of ages we have to specify the value in indexes.conf and by default it is 250000MB. Does that mean each and every bucket will hold the data till it reaches 250 GB - Say Hot bucket will hold the data till it reaches 250GB then it transfers to Warm and then Warm will hold it reaches 250 GB and it goes on like that?
OR
is that 250 GB applicable only for Frozen bucket if so on what condition other buckets will roll out the data,Can any one please clarify?
Thanks
... View more