Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forwarder? I am trying to test functionality on small subset of endpoints before adding a heavy forwarder into the server class on the deployment server.
Of course! Just put your limited outputs.conf
file here on the UF:
$SPLUNK_HOME/etc/system/local/outputs.conf
Then restart Splunk on the UF.