End of last year we migrated from Splunk 6.5.3 to 7.1.3
The universal forwarders on the different source systems delivering our inputs,
send data via a load balancer to 2 intermediate forwarders, connected with our 6 indexers.
That setup was recommended to us a few year ago (by a splunk partner) with the initial setup of our system.
We found information indicating that the best setup recommended today is a direct connection between universal forwarders of the source systems and the indexers of our splunk cluster (no intermediate forwarders with a load balancer).
Anyone who can comment on this?
Good question and I could see lot of variations/personal views on this setup. But please find my experience and some inputs