We have an established Splunk Enterprise production environment that several departments use. Some people want to develop new searches, but are worried about disrupting the production environment. Do you have any best practices for setting up a safe test environment that feeds the production workflow?
↧