This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6
To back up your configurations, make an archive or copy of $SPLUNK_HOME/etc/ (where $SPLUNK_HOME is the directory into which you installed Splunk, /opt/splunk by default). This directory contains all the default and custom settings for your Splunk install, and all apps, including your saved searches, user accounts, tags, custom source type names and configuration files.
Copy this directory to a new Splunk instance to restore. You don't have to stop Splunk to do this.