How do I backup the Splunk Enterprise Security app. What components needs to be backed up and how often? I have already documented a short plan to backup the Splunk Enterprise.
Is it in a search head cluster environment?
Also though, backing up theKV store is part of Enterprise:
https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/BackupKVstore
but should be done prior to upgrading ES:
https://docs.splunk.com/Documentation/ES/6.5.1/Install/Upgradetonewerversion