First off thank you for the response, we are sub 50 clients currently on the deployment server but very helpful information if we decide to expand. I probably should have been a little more specific regarding the alert. I am leveraging Splunk cloud for email alert, I would like to be able to index logs locally and forward them because I would like to be able to kick off local scripts on hosts which I was under the assumption would have to be local to the network. It would be limited inputs I would want to do this with like sub 5 hosts. Do you know what kind of licensing is required to index with Splunk Enterprise on prim?
... View more