The applications, "Splunk Hadoop Connect" and "Shuttl", serve very different use cases, and thus differ in functionality.
Shuttl provides archival/restoration of Splunk indexes, supporting HDFS as an external file system to send and retrieve this data. As noted in the documentation, this archival can occur when buckets go from warm-to-cold or cold-to-frozen.
Splunk Hadoop Connect is intended to reliably export, explore and import of data between Splunk and Hadoop for use between applications. As such, it provides export features such as:
- Splunk search driven which allows you to search subset of your data, append other data, perform lookups, modify/scrub
- Set export format
- Set dynamic partitioning schemes
- Set granular export frequency
In short, it really depends on what you are looking to do here.