Hello,
I understand from some of the links that using UFs as intermediate forwarding layer add metadata at **stream level** while using HFs as intermediate layer add metadata at **event level**.
What is the general increase of daily log transmission size, (say when we are expecting 200 GB of daily data) when passing through this on-premise intermediate layer to Splunk Indexers hosted on an external cloud?
Please advice.
↧