Hi,
how can we send ES notable events from cluster setup to a stand alone indexer.
Tell us more, please. What problem are you trying to solve? What is the "cluster setup" - indexer or SH cluster?
we have main setup with indexer cluster and a search head with ES over it and a small setup consists of an indexer and a search head.
we need to forward all notable events from the main setup to the small setup.
how can we do that?
I sounds like you're referring to Index and Forward. See https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_...