Hi,
i would like to use one of my universal forwarder as a second indexer. Please help me how to do it.
In the second step i would like to configure that all forwarders send data to both indexer in a loadbalancer mode.
Can you help me please?
thanks
You cannot use the Universal Forwarder to index events. In order to have an extra indexer, you need to install a the full Splunk product.
/K