Hi,
If there is no need/requirement for local indexing, it can be disabled:
Go to Splunk install directory
cd bin
./splunk disable local-index
./splunk restart
You can explicitly define your data inputs in your inputs and outputs.conf. Assuming it's a Linux env and you are using default ports..Eg:
inputs.conf
[script:///Path to your script]
disabled = false
interval = your_interval (cron or secs)
sourcetype = your_sourcetype
index = your_index_on_cluster
outputs.conf
[indexAndForward]
index = false
[tcpout]
defaultGroup = your-group
[tcpout:your-group]
server=idx1:9997,idx2:9997,idx3:9997
... View more