From can I see, Splunk continues to run but I would like to know what happens to the cold data which meets the criteria to be frozen? Once the frozen directory is made accessible, does Splunk continue to freeze the data, or was it already removed from the index?
What occurs is the following.
If no action is taken to resolve the issue, the disk will eventually fill up and all indexing will stop.