First a few words about my setup.
I have a distributed setup with the following nodes
Forwarder (Lets call this the 'Light Weight' forwarder )
I have some devices whose logs are transferred using their forwarder (Lets call this the Universal Forwarder).
The universal forwarder send the logs to the light weight forwarder which just pass them on to the indexer.
Now, I am trying to migrate from Splunk 4.3 to Splunk 5.0. During this process, the splunk process on the indexer node should be stopped.
My question is, should the light weight forwarder also be stopped while migrating the indexer to prevent data loss? Will splunk keep the data in the pipe of the light weight forwarder when the indexer is down or will it keep on sending resulting in data loss?