By "sinkhole", I assume you mean the ability to copy a file into $SPLUNK_HOME/var/spool/splunk
, and have it indexed then automatically deleted by Splunk. Yes, it is enabled on both heavy (SplunkForwarder
) and light (SplunkLightForwarder
) forwarders.