1) In a distributed environment, search heads and indexers are on separate [virtual] machines. You can have two servers, but one of them will be a SH and the other will be an indexer. The usual procedure in this migration is to make the standalone server become the indexer so no data migration is needed. 2) Non-clustered indexers do not need to have the same storage. They must have enough to hold whatever data they will ingest over the expected retention period, plus about 10-15% for overhead. Keeping all indexers the same will make for easier management. 3) Yes, I'm sure someone does. I am not one of those people, however. 4) You can reduce the number of CPUs or the amount of memory to save money as long as performance meets your expectations. Understand, however, that if you ask Splunk for support they may ask you to bring any under-provisioned servers to minimum specs before assisting you.
... View more