We have a single Splunk Enterprise server deployment. Recently, we migrated it to newer hardware (SSD drives, etc). The old machine is still a decent piece of equipment, just has less disk space. I've been reading about clustering, or adding an indexer. Would like to make use of the old machine for additional index storage and search, but it seems not worth doing a cluster with only two machines. Also, if I just added an indexer role, I have concerns about re-pointing forwarders there, etc. Any ideas? Anyone else been through something similar, where your older machine had not been "stolen" away and you can make use of it? Thanks in advance!
... View more