I want to achieve HA for Splunk Heavy forwarder.
I have to deploy 2 Heavyforwarder in HA. The UF can send the load balanced data, for syslog i will use external load balancer.
But i am stuck on 1 thing. How the logs/events will be load balanced is i install Splunk App on the Heavyforwarder? Is there any solution if i want to use any Splunk App on Heavyforwarder in HA.
If i install same splunk App on both the heavyforwarder then the data will be duplicated?