Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.
Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)
Unfortunately you are in unsupported territory. From the documentation:
The search heads must run the same or a later version from the peer nodes.
Despite wanting advice different from "upgrade your search head", that's likely your only viable option.
That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...
@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.