Hi @BoscoBaracus , at first, clustered Indexers are managed by the Cluster manager and Heavy Forwarders by Deployment Server, and it isn't a best practice to use the same server for both the roles, ...
See more...
Hi @BoscoBaracus , at first, clustered Indexers are managed by the Cluster manager and Heavy Forwarders by Deployment Server, and it isn't a best practice to use the same server for both the roles, especially if the DS must manage more than 50 clients. Anyway, the situation is the same: on the HF, you have to configure all log forwarding to the Indexers, on the HF you have to create soma inputs indicating the indexes to store data, in this way all your logs are forwarded to the correct indexes. Just some addition hints: for syslogs, don't use Splunk network inputs but rsyslog that writes syslogs in a file taht you can read on your HF, to address clustered Indexers, use Indexers Discovery feature (https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/indexerdiscovery). As anticipated, don't use the Cluster Manager as Deployment Server, use a different server, possibly dedicated: if you have few clients to manage (less than 50) you can use another server of your Splunk infrastructure, but not Cluster Manager or Searcjh Head or Indexers. Ciao. Giuseppe