We are in the midst of a migration from physical servers to virtual servers, and we wonder if stopping Splunk is mandatory in order to perform the Cold Data migration or if there’s a workaround to this and this can be safely done without stopping Splunk.
Warm and cold buckets can be copied safely while Splunk is running. You don’t necessarily need to stop Splunk to perform the cold data migration.
Refer the below link:
Warm and cold buckets can be copied safely while Splunk is running.