Intro

Recently, we worked with a client that was using a multi-tiered storage configuration for their Splunk deployment.  One tier was used for hot/warm data and the other tier for cold storage.  We wanted to test the cold storage tier specifically.  We used the Splunk event generator to produce data and tweaked some index settings to generate buckets (if you haven’t used the event generator before, here's a previous blog post for reference). 

Index Configuration

In the...