I am testing the frozenTimePeriodInSecs setting, so I have edited my /opt/splunk/etc/system/local/indexes.conf and added the following:
[default]
frozenTimePeriodInSecs= 180
and restarted the app. Immediately afterwards, I searched for index=_internal source=*splunkd.log BucketMover and verified that the message AsyncFreezer freeze succeeded appears.
Then, I uploaded some logs in the main index and waited some time, but no new AsyncFreezer event has been executed again and the log information I loaded is still there. Even after the 180 seconds have elapsed.
My expectation is that the AsyncFreeze event is executed on a regular basis and the data recently uploaded is no longer available in the Search.
What am I missing?
TIA
... View more