I am building a lab environment at AWS and I would like to know which one is the best approach for sending the logs from the forwarders.
Based on the image which one will be the right approach?
A - Send the logs from the forwarders into the master cluster and the master cluster forwards them to the indexers?
B - Send the logs to the 1st indexer and the master cluster will handle the replication?
C - Send the logs to any indexer and the master cluster will handle the replication?
D - None of the above
I have tried to look for documentation regarding this issue but have not been lucky finding it, if anyone can point me in the right way I will appreciate it.
as you said there are two approaches:
you can address each Indexer in outputs.conf file of each Universal Forwarder (the best approacch is to manage outputs.conf in a dedicated App to deploy with Deployment Server), but in this way, if you add a new Indexer you have to modify outputs.conf and deploy it;
you can address the Master Node (not sending logs to it!) and it says to Universal Forwarders the active Indexers, in this way you don't need to modify outputs.conf in every Universal Forwarder.