Hello, We have one universal forwarder, and two cloud instances. Currently I have all data going to 1 indexer, I've been attempting to determine the most efficient way to parse and route the data so that it will go to the correct indexer/splunk instance without effecting ingest volume. If I ingest everything into the "primary" indexer can I just parse and route that raw data to the "secondary" indexer without effecting ingest volume on the "primary"? I was originally going to use a heavy forwarder for the parsing and routing but sounds like that may be more network IO intensive.
... View more