We are currently running Splunk in single instance mode and have grown enough that we need to expand it. I have the ability to provision an existing beefy server to be a second indexer. However, I do not have the hardware to have a dedicated search heard.
My reading of the splunk documentation is that I will need 3 servers minimum (1 SH, 2 IX). Is that correct? Is there no way to do "just add a second index" (management question)?
Have you thought of virtualizing - if the server is "beefy" you could potentially do that..It has its benefits and its drawbacks - see below https://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf
You will need min 3 physical servers if you want a distributed environment, im sure you could somehow hack around this but you wouldnt get any performance gain.
Have you thought of virtualizing - if the server is "beefy" you could potentially do that..It has its benefits and its drawbacks - see below https://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf
You will need min 3 physical servers if you want a distributed environment, im sure you could somehow hack around this but you wouldnt get any performance gain.