Hi @gcusello @PickleRick, Thanks for the quick reply. Correct, our 3 HF receive data from syslogs behind a F5 loadbalancer, they are all in active/active mode and the loadbalancer distribute data on each HF. These HF should be use also to pull data to various cloud. If I understand well splunk does not propose a solution out of the box for this case. As our Search-Head are in cluster mode I could maybe continuously searching HF failure in logs (F5 logs) and configure an alert with a script to enable the TA with API call or whatever on another HF in case of failure. In that case we also need to configure rsync or other to copy checksum to other HF node to don't pull all data again. I may overthinking and complexify too much
... View more