How to do that? As far as I know, I can get data into single index, how about Splunk cluster? Should I specify connection to master node? What if master node goes down?
Don't send data to a master node. Send it to the Indexers withing the cluster. Review outputs.conf for the forwarders, and the distributed architecture of Splunk.
If you setup the output of the forwarder to output to each indexer, Splunk will auto load balance for you and send to all the configured indexers.
should I open connection and send the same data to each Indexer in a cluster?