I’m relatively new to Splunk and currently designing my first production architecture, so I’d really appreciate your guidance. I’m considering a Multisite Indexer Cluster, but due to current constraints, my plan is: Start by implementing the entire environment in one site (HQ) After a few months, build and add a DR site Eventually convert this setup into a full multisite cluster My questions are: Is this approach recommended or supported by Splunk? Are there any design decisions I must take from day one to avoid rework later? Would it be better (for a beginner) to: Start with a single-site indexer cluster, then migrate to multisite later? Or design it as multisite from the beginning, even if the second site doesn’t exist yet? I want to follow best practices but also keep things simple and safe, especially since this is my first real
... View more