You'll need to update your 4.0.9 indexer to 4.2.1 before this is possible. Between 4.1 and 4.2, the data format that raw data is written in was changed. The formats are not compatible with one another. Copying over the saved searches themselves aren't a problem, you'd just need to copy the savedsearches.conf files over from $SPLUNKHOME/etc/apps//local/. Once you get the 4.0.9 system up to 4.2.1, you can simply copy the indexes.conf file that references the index from the location where it exists from the old system to the new one. To copy the index over, stop splunk on both systems and copy the $SPLUNKHOME/var/lib/splunk// to the same location on the server you where you want the index to exist moving forward.