Data in Splunk indexes is stored in directories called buckets. Each bucket moves through a lifecycle of stages as it ages.
Hot buckets are actively being written to. Warm buckets are closed for writing but still searchable on fast storage. Cold buckets are archived to slower storage but remain searchable.
Frozen buckets are removed from the index (deleted by default or archived). Thawed buckets are previously frozen data that has been restored for searching.