Couple questions about the Splunk Add-on for Box. We're setting up a heavy forwarder to collect the data. Do we need to also install the add-on on both the Search Heads and Indexers as well, or just the Search Heads?
I'm also trying to determine how much disk space is needed on the heavy forwarder VM. Do the Box logs get stored on the heavy forwarder or do they get passed directly to the Indexers, without a copy being saved?
Appreciate the help.
Thanks!
↧