Hello @gcusello, yes understood. But in my use cases I am talking about logs coming directly from udp or tcp, not from UF. For instance in the Palo Alto documentation, it is literally said to configure this udp or tcp input (via GUI or CLI) to forward data from Panorama instance to Splunk Indexer or HF : https://splunk.paloaltonetworks.com/firewalls-panorama.html#gui So here, if I do not want to have a Single Point Of Failure, I need to have a load balancer between the Panorama machine and my 2 HF listening for incoming network logs. I also cannot tell my Panorama to send the logs to the two HF otherwise I would end up with duplicated events. Thanks for your time, GaetanVP
... View more