I have a pair of HFs located in a DMZ that can collect data from the Internet via a script input.
All other Splunk instances (indexers, SHs, deployment server etc) are firewalled from the Internet.
Only one of the HFs can run the input for any collection period as the data is large and duplicate events would not be acceptable so running the script on both HFs isn't suitable.
At present I configure the input on just one of the HFs but I'd like to be able to have the script automatically executed by either HF in case of HF failure.
Has anyone solved this problem?