In my company we set up our Splunk to use a Search Head Cluster and a Indexer Cluster but I want to make a separate Splunk instance (not in the sh-cluster) use the indexers. This is meant to be a "developers" instance and I want to keep the environment to a minimum by opting out of things like shcluster redeploys, bundle replication, scheduled searches, etc...
Is there a way to configure a search head to work like this?
It certainly is possible. Use steps from following link to setup a search head to use indexer cluster peers.
http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Configurethesearchhead
Please be aware that having a Development instance querying a Production Indexer cluster will cause additional load on the Indexers, as well as there might be a risk where developer may accidentally delete prod data, so keep a close control on access if you really have to implement this way.
It certainly is possible. Use steps from following link to setup a search head to use indexer cluster peers.
http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Configurethesearchhead
Please be aware that having a Development instance querying a Production Indexer cluster will cause additional load on the Indexers, as well as there might be a risk where developer may accidentally delete prod data, so keep a close control on access if you really have to implement this way.