I am looking for a best way to prepare for disaster recovery to a remote site.
We have 5 nodes indexer cluster and wanted to get the best backup and strategy so I can create a daily backup that can be , in case of disaster, restored to a single server instance of Splunk enterprise to provide minimum functionality during main site unavailability.
The strategy I am looking for should be able to construct a single tar compressed file that consolidate all buckets from the 5-node indexer cluster and restore it to a single node server.
is there a way to construct a single backup (no bucket replication) from an indexer cluster?