Hi
We are planning to decommission splunk enterprise in our environment. We need to stop sending data to splunk . How should we proceed , from where we should start? Can we find any SOP for this decommision process. But we want to store the indexed data for more than 365 days .
This is new task we are handling for the first time , any proper guidance will be much appreciated.
Thanks in advance.
Hi
Here is some guidelines what you can /should do, but probably this list not cover all steps what you need to do.
r. Ismo