We have an Splunk architecture with about 7 indexers, 3 search heads, 2 Heavy forwarders and a deployment server. We want to stop further data ingestion permanently but keep the servers up for searching historical logs. Can you please advice two or more methods to do so. Thanks in advance.
... View more