I assume that your autoscaling have installed splunkforwarder with initial configuration to connect eg. DS to get the real and updated configuration. Also I am assuming that you have some naming schema to known which Splunk’s serverclass this node belongs. Then there shouldn’t be any big issues to manage autoscaling. Of course if you have huge amount of events hundreds/thousands / second and your node crash then you could lost some events.