My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.
If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.
Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?