When we first rolled out Splunk to our forwarders we installed the full version. We would now like to convert them to Universal Forwarders to reduce the footprint on the servers. All the documentation talks about converting from a light forwarder to a universal forwarder and using the MIGRATESPLUNK=1 option to convert the checkpoint data. Will that also work when going from a Heavy Forwarder to a Universal Forwarder?
... View more