I want to send windows logs through heavy forwarder to indexer.
on windows server, I install universal forwarder and put Heavy forwarder ip:9997.
already configure listening on heavy forwarder.
now how can I see event in indexer.
why would you want to use a Heavy Forwarder?
try and avoid using HF unless you must have it
take a look at this link to troubleshoot:
Just have a look at the inputs.conf spec and accompanying examples. Or check out my accepted answer here: https://answers.splunk.com/answers/648353/how-to-limit-a-data-sent-to-indexers-to-only-with.html