Thank you very much for your response. I have a follow-up question. If I have two Search Head Clusters (SHCs), one dedicated to Enterprise Security (ES) and another for general Splunk use, is there a way to provide users with a single access point (one URL) where they can work with data and content from both environments? Ideally, I would like users to log in only once and have access to everything they need, including ES dashboards, investigations, and searches, as well as general Splunk apps, dashboards, and searches. Is there a recommended architecture or best practice for achieving this?
... View more