Back up configuration information
All Splunk's configuration information is contained in configuration files. To back up the set of configuration files, make an archive or copy of
$SPLUNK_HOME/etc/. This directory, along with its subdirectories, contains all the default and custom settings for your Splunk install, and all apps, including saved searches, user accounts, tags, custom source type names, and other configuration information.
Copy this directory to a new Splunk instance to restore. You don't have to stop Splunk to do this.
For more information about configuration files, read "About configuration files".
Back up the cluster manager node
If you're using index replication, you can back up the manager node's static configuration. This is of particular use when configuring a stand-by manager that can take over if the primary manager fails. For details, see "Configure the manager" in the Managing Indexers and Clusters manual.
Configuration parameters and the data pipeline
Check the integrity of your Splunk software files
This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1