We are having this same issue, 7 years later on Splunk 9.04.1. Has anyone identified a solution? We have a cron job running every 6 hours which deletes all files. Additionally, we added an IgnoreOlderThan = 6h to our inputs.conf, but it did not make any impact and we are still using 100% swap memory, instead of system memory.
... View more