can we install the splunk instance as an indexer and universal forwarder in the same machine and try to forward data beteween them
why would you want to do that as an indexer can collect data directly too (and even forward data to another indexer or 3rd party ie:syslog-ng)?
If you still want to do that you will need to change splunkd listening port 8089 on one of them.
View solution in original post
Yes, in normal circumstances really no need to do this since the indexer can directly do everything the UF can do. However, this can be useful for testing purposes, or for some more complex load-balancing or failover purposes.