Hello Splunkers!
Here is the case.
We already have clustered indexers on-premise and thinking to get an additional indexer server on our cloud system and adding to the index cluster on-premise.
What would be the considerations and cons?
Thank you in advance 🙂
I'll assume you have a private cloud rather than Splunk Cloud.
Pro: additional indexer capacity
Cons: latency; data egress charges from the cloud provider