Splunk by default will stick on a given indexer for 30 seconds from a heavy forwarder before connecting to another. This can lead to inconsistent load balancing but there are things you can do to tune it better.
Your concern about Netflow into Splunk also creating a lot of connections via Splunk isn't a valid concern. Splunk sends megabytes or gigabytes of data per TCP connection before establishing another connection. There may be thousands or millions of Netflow records in that stream. Splunk should not meaningfully add to your Netflow record count from HWF to Indexer. On the front side of the HWF, depending on the number of Universal Forwarders though, you could see a significant number of connections. Enough to be a meaningful percentage of your Netflow data.
... View more