We hard-code the indexers in the outputs.conf
at the moment. How can we detect the indexers automatically by the forwarder and avoid the hard-coding ?
By using indexer discovery the forwarder can detect indexers. This of course requires that your indexers are setup in an indexer cluster. The forwarders would contact the indexer cluster master to receive the peer list from the CM so adding new indexers to the cluster doesn't require editing outputs.conf anymore on your forwarders:
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/indexerdiscovery
By using indexer discovery the forwarder can detect indexers. This of course requires that your indexers are setup in an indexer cluster. The forwarders would contact the indexer cluster master to receive the peer list from the CM so adding new indexers to the cluster doesn't require editing outputs.conf anymore on your forwarders:
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/indexerdiscovery
Much appreciated @rphillips!