How does Splunk handle events when forwarded? Does it send them one event at a time or in batches?
I.E.: I am using a heavy forwarder to send a copy of my data off site through a router that collects NetFlow information. My concern is will the recursively created NetFlow records increase uncontrollably if it is monitoring its own output?
Netflow is set to capture session data and then forward it to Splunk.
... View more