Hi, everyone! I have the following architecture: In my main office, I have Splunk Cloud and Splunk ES, and in a remote office, I have Splunk Enterprise and Splunk ES. I am looking to achieve two things: Federate the data from Splunk Cloud to Splunk Enterprise. Consolidate my environment to avoid having two Splunk ES instances (Cloud and Enterprise) and use only the "Splunk ES" version on Splunk Cloud. Is this possible? Does Splunk ES function correctly if I attempt to pull federated data from Splunk Enterprise?"
... View more