Hi,
We have been seeing replicated buckets starting rb_ in the frozen buckets. Is there a way to exclude the rb_ buckets from archiving?
Here is our doc that discusses backing up data on an index cluster: Clustered data backups . As described in the document, there isn't a straight forward solution for this. Others may be able to provide a solution they've implemented but "out of the box" this is how it works. There could be a more ideal solution provided in a future release though. If you have a Splunk Account Manager, you can ask them to submit an Enhancement Request on your behalf.