I am having the exact same issue. I have opened a case with Splunk Support, but all they did was copy and paste the response kheo provided.
In our environment we have not restarted Splunk for months, so this is not the cause of it prematurely rolling hot buckets.
... View more