indexes.conf is set to read only
I can't even change my frozenbucket retention period
If you are on the indexer, check the path /opt/splunk/etc/system/local/indexes.conf
so where do I edit indexes.conf?
Are you attempting to edit the file in the default directory? If so, you should be overriding the entries in default with a file in the local directory. See the docs for more info.
Make it writeable?