So I am in somewhat of a fun situation where we have multiple instances of Splunk installed each with their own index clusters and search head clusters. I know you can configure search heads to search multiple index clusters, but not all my index clusters have the "same" data in a named index (mainly, index=main). So what I was wondering is if I install all the apps from all of the instances onto the search head cluster that is configured to connect to all index clusters, I can tell those apps to only look to the appropriate index cluster that has the data they want? I think I could accomplish this with sites maybe if I can tie an app to a site. But I am not finding either index cluster or site configurations for individual apps. The point would be to provide a single place to login and be able to see all the splunk data and to eventually retire the now extraneous search head clusters without the apps having to search multiple "main" indexes in clusters that don't have the data they are looking for.
... View more