Thanks for your reply. But Can i send the logs to other siem solution from UF along with indexers?
Also, can i setup search head (just to see what logs are coming not for actual searching) on same indexer node?
Is there any chance that i will loose my logs if i will setup indexers in non clustered mode over two DC.
... View more