Is it possible to send logs to S3 from a heavy forwarder? I have seen information about being able to ingest from S3. Please advise. Any information can help.
Yes, it can be done using Ingest Actions. See https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/DataIngest#Create_an_S3_destination