Thank you, I randomly ran it for a few buckets and observed the following message: Moving bucket='rb_1681312487_1677890027_1731_FBA51F26-2043-4798-B18D-2D637A7347B9', initiating warm_to_cold: from='/Data/splunkdb/o365/db' to='/Data/splunkdb/o365/colddb', caller='chillIfNeeded', reason='maximum number of warm buckets exceeded'. I'm not sure if this is the reason that could be affecting the data retention period. Initially, I had "maxHotBuckets = 10" defined, but it's no longer defined, and I've left it as the default value. [test] coldPath = volume:primary/test/colddb homePath = volume:primary/test/db thawedPath = $SPLUNK_DB/test/thaweddb maxTotalDataSizeMB = 512000 frozenTimePeriodInSecs = 39420043
... View more