I have a heavy forwarder currently sending data to Splunk Cloud.
Can I use the same heavy forwarder to stop data sending to Splunk Cloud and start sending data to on-premises Splunk?
If yes, then how?
Change the forwarder's outputs.conf file to point to your on-prem indexers. You'll also need to change the security settings to values appropriate for your on-prem environment.