Back up configuration information
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Back up configuration information
To back up your configurations, make an archive or copy of $SPLUNK_HOME/etc/ (where $SPLUNK_HOME is the directory into which you installed Splunk, /opt/splunk by default). This directory contains all the default and custom settings for your Splunk install, and all apps, including your saved searches, user accounts, tags, custom source type names and configuration files.
Copy this directory to a new Splunk instance to restore. You don't have to stop Splunk to do this.
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.