Hi colleagues,
I've still trying to find an answer to my questions here, but it seems there is nothing helpful to me.
We've got two Splunk Instances: the first one is a ****Heavy Forwarder**** and the second one is a **Indexer** and **Seach Head**.
To minimize workload on Seach Head I tried to turn on indexing ( `indexAndForward`) on HF and found that Splunk started using the licence twice faster than it was before. And just to clear understand I'd like to know does Splunk try to index data in the second time even if it already did it on HF? If yes why? and what could you propose? Thank you.
↧