hi https://github.com/mehransafari/Splunk_Frozen_Cleanup this is a script that will find frozen logs older than X days and will ask you to remove them if you want it may help you
... View more
This looks pretty good so if you are still looking for performance/safety improvements, I suggest that you convert from using SI to using accelerated data-models + tstats.
... View more