We have a contract coming to its end and need to close Splunk for them, but we still need all the data accessible afterwards so that it can be loaded into a different Splunk instance if required.
We had to do this with an old standalone instance when we purchased hardware for a clustered environment. Here's what you need to do:
Hope this helps