hi,
I have two teams each running their Splunk deployments and I need to have a centralized manner and woud like to be able of accessing the data and run my ML algorithms on subdata sets from both splunks.
how is it possible ?
how can I connect to two Splunk at the same time ?
thanks
-Bill
You could stand up a new Splunk search head and configure it to use both sets of indexers as search peers. Specifics depend on the nature of the two silos.