We are currently running Splunk in single instance mode and have grown enough that we need to expand it. I have the ability to provision an existing beefy server to be a second indexer. However, I do not have the hardware to have a dedicated search heard.
My reading of the splunk documentation is that I will need 3 servers minimum (1 SH, 2 IX). Is that correct? Is there no way to do "just add a second index" (management question)?