I'm working on an existing Splunk environment where 1 Search Head and 2 Indexers are installed. Now I need to install the Splunk Add-on for Amazon Web Services. Should I install a heavy forwarder just for the AWS add-on? Or can I use Search Head which is not recommended and I'm getting this warning "Configuring this add-on on a search head is not best practice." What is the side effect of using Search Head for AWS add-on?
↧