Hi shariinPH,
If you haven't set any coldToFrozenScript
in your indexes.conf
your old events will not be archived http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Automatearchiving
That said, if you're using all default settings for your indexes, Splunk will delete any old events for you.
Check the docs for more details on that http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Setaretirementandarchivingpolicy
Hope that helps ...
cheers, MuS
Thanks @MuS !!:)
If this answers your question, please accept it - thx 🙂