Hi everyone. We have a single Splunk entreprise instance. We are planning to set frozentimeperiodinsecs in a legacy index that has not been used any more. For example, I have the setup below. name size event count oldest data newest data indexA 420GB 3.06B 6 years ago 3 months ago indexB 370GB 1.22B 7 months ago few seconds ago main 270GB above 200M 6 years ago 3 months ago We are indexing data on IndexB now and are not using indexA & main any more, so we are planning to shrink its size to maintain disk space. We don't want to delete it at once since we have compliance requirements and have to keep data for one year. My question is, if I set frozentimeperiodinsecs(in local indexs.conf 's indexA, main stanza) to 1 year(31536000) on, when Splunk manages to delete it? Do I have to reboot Splunk? or delete it with search commands manually? someone please help me.
... View more