Back up configuration information
All Splunk's configuration information is contained in configuration files. To back up the set of cofiguration files, make an archive or copy of
$SPLUNK_HOME/etc/. This directory, along with its subdirectories, contains all the default and custom settings for your Splunk install, and all apps, including saved searches, user accounts, tags, custom source type names, and other configuration information.
Copy this directory to a new Splunk instance to restore. You don't have to stop Splunk to do this.
For more information about configuration files, including the structure of the underlying directories, read "About configuration files".
Back up indexed data
Set a retirement and archiving policy
This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7