Scenario: Two large organizations with two separate Splunk implementations. Org A acquires Org B and in a consolidation effort they'd like to consolidate their search heads and search 2 indexer clusters.
What are some approaches to this? One caveat is both Org A and Org B have some overlapping index names (ie both have index=network).
Is it possible to give a role a "default" cluster, so anytime OrgA user searches, they default to OrgA, BUT can be overridden by specifying splunk_server_group=OrgB or splunk_server_group=* ?
A search head can search multiple indexer clusters. That's a supported configuration. Separate clusters will always have some overlapping index names (such as _internal).
It's up to the user to filter the desired results when search data comes from more than one cluster.