We want to reinstall splunk so that it will run as user splunk. Can we just copy the old etc directory structure over to the new installation, so that it retains its current configuration?
I am not concerned with saving any of the indexed data.
It is pretty straightforward with simply copying the right folders. Take a look at this for more details.