Splunk stores data in indexes organized in a group of buckets sorted by age. The hot buckets stores the data that is presently being written to. This will be later rolled to the warm, cold, and frozen buckets. The hot bucket cannot be backed up but Splunk has the feature to create a consistent snapshot of the other buckets. This can be done using incrementing ongoing backups or a single backup of total data. Taking snapshots at regular periods from a healthy environment allows you to recover from the last valid checkpoint in the case of any sudden unfortunate event.
If you are looking for an online course, then enroll in this Splunk Certification program by Intellipaat which has experienced instructors, best curriculum, and hands-on projects.
Also, watch this video on Splunk Architecture: