Thanks for the explanation. However, I will like to know if it is ideal for the Heavy Forwarder to be forwarding to the Indexer Master?
I understand that the Indexer master is not part of the Indexer cluster and it only control the activities on the IDX cluster, but i am just just curious how do it do that.
My question:
1. Can the HF ----- IDX MASTER ? Can the HF forward data to the IDX Master too?
2. Can the Indexer Master be added to the RECIEVING PEERS like the Indexers?
3. If we have 2 HF and we want to forwarder data from UF to the HF, do we have to run the command to forward logs to the HF:9997 twice to achieve that?
4. Is there any way to cluster Heavy Forwarder in SplunK
Please advice
... View more