my Heavy forwarder is forwarding events to Splunk indexers. Does link breaking , aggregation etc takes place on indexers again?
If not is there any way to make events to undergo parsing on indexers even though they already got parsed on Heavy Forwarders?
↧