I am using Universal Forwarder as Intermediate forwarder, it is forwarding the monitored data without any issues but it is not forwarding any data _internal index or Splunk logs.
Intermediate Forwarder Configuration:
Outputs.conf
[tcpout:index]
server=sra-index-01:9997,sra-index-02:9997,sra-index-03:9997,sra-index-04:9997,sra-index-05:9997
inputs.conf
[splunktcp://9997]
disabled=0
[tcpout]
forwardedindex.filter.disable = true
[tcpout]
forwardedindex.filter.disable = true
Thanks dmaislin, it worked.
Worked for me as well.