Hi All,
I am investigating the possibility of consolidating our separate standalone ES Searchheads into a single clustered ES instance. Due to network segmentation rules, my indexer clusters will have to remain separate. My question is, can Splunk ES utilise separate Indexer clusters from the same ES Searchhead cluster, in the same way that non-ES searchhead clusters can?
If it is possible, are there any gotcha's to be aware of?
Thanks in advance.
Waja1n0z1