Hello,
we have decided to retire SPLUNK and the server that SPLUNK was running on. If the server is decommissioned, do we still need to decommission SPLUNK - or would one equal the other? If it wouldn't, is there a way to still decommission SPLUNK after the server has been decommissioned?
Thank you.
From Splunk's perspective, no action is needed to stop using the software. Your company, however, may have its own requirements, such as archiving the data before decommissioning the server.
thank you for your response! Yes, what I am referring to is just no longer using SPLUNK at all, not just one indexer. The question was more in terms of any scripts or data that was not removed from SPLUNK specifically before decommissioning the server.
It depends on what is meant by "decommissioning Splunk". There is a process for removing a member from a search head or indexer cluster. Decommissioning an independent indexer typically would mean moving that indexer's data to another indexer.
If you will not be running Splunk anywhere then just stop Splunk and retire the server.