I realize buckets die off as the newest event surpasses the expiration date. I also understand that deleting events do not remove the events, simply mask them from appearing in search results.
My question is, do deleted events count when Splunk decides on when to expire a bucket file? In other words, does deleting an event remove it from Splunk's calculations for expiration? I am looking for a way to manage an index corrupted with future events, other than manually deleting very old files manually, when the time comes. The other events in the index are valid and needed.
I am using Splunk version 4.3.4, soon to be upgraded to version 5.x.
This is related to my Splunk-Base "How do i configure an index to manage future events" question. An answer here or there may solve both.
Please correct me if I misunderstand anything and thanks for the help!