I am evaluating the SPLUNK with windows version. I want to clarify the following questions:
1-I think currently it's not possible to do SMTP auth but it will be in 4.2. The workaround could be to use a scripted alert where inside your script you can configure smtp auth.
2-When Splunk is indexing, the data moves through a series of stages and you have info about backup strategy here http://www.splunk.com/base/Documentation/latest/Admin/BackupIndexedData and about indexes partition http://www.splunk.com/base/Documentation/latest/Admin/HowSplunkstoresindexes
hope this help