I am planning to migrate from an all-in-one Splunk instance to a Splunk cluster. I am thinking about turning the old all-in-one Splunk instance into a search head in the cluster.
So my idea is that the new servers for the cluster will start indexing/replicating any data after the cut and have legacy data in the search head.
Would this give me access to the legacy data? Any issues that I am not thinking about.