Hi All,
I have inherited Splunk Enterprise in my company which includes 3 Indexers, 2 Search Head and each Deployment & Licensing Master and Cluster Master.
Now in order to receive events from more than 250 servers, Do I need to setup a separate Heavy Forwarder (server) or can we use the above setup/configuration and use one of them as heavy forwarder.
Thanks,
↧