Our client is asking us for information that is stored in the Splunk cloud, and I am not aware of how to access a copy of the information, either because they simply want to have it or because they want it to be backed up from time to time.
The second part of the question is if there is such a way to have a copy of that information how is the restore process?
What information does the client want? Some may be available via the UI, but most will have to come from Support. Other information may not be available at all.
Be aware the Splunk Cloud makes regular backups of each stack.
One of the data sources is from a database that is being sent to Splunk is what is collected via the dbconnect plugin.
Data ingested using DBX is indexed. You should be able to run a search and export the results. That's probably the best you can do as I doubt Splunk will give you a copy of the buckets.