By "sinkhole", I assume you mean the ability to copy a file into $SPLUNK_HOME/var/spool/splunk, and have it indexed then automatically deleted by Splunk. Yes, it is enabled on both heavy (SplunkForwarder) and light (SplunkLightForwarder) forwarders.