I'm thinking about combining the three roles of Cluster Master, License Master and Deployment Server on the same Splunk enterprise instance. The cluster contains three indexers and all search heads are standalone.
Currently, we have around 400 forwarders using the DS and we're running Splunk 6.5.9. (Going to upgrade early next year). The current DS needs to retire and I would prefer to minimise the footprint of the entire environment.
Will this setup work well or will I see performance issues?