@Glasses2 I would also plan similarly in your scenario, on the Edge processor nodes, you can position them close to the data sources for enrichment and routing. This is acceptable, but generally for high-volume syslog ingestion, Splunk Connect for Syslog (SC4S) remains the recommended solution. Overall, UFs feeding Cloud indexers, DS for management, EP or SC4S for syslog, and HFs only where necessary. I would highly recommend you refer Splunk’s Validated Architecture documentation for definitive sizing and placement. Hope it helps. Ref: Splunk Validated Architectures >> If this post addressed your question, you can: Give it karma to show appreciation 👍 Mark it as the solution if it solved your issue ✔️ Add a comment if you’d like more details ✏️ Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise. >>
... View more