Using Splunk functionality, I see that you can enable data cloning/replication either by:
a) configuring a forwarder to load balance over indexers in a primary cluster and also clone data to a indexers in a mirrored cluster
b) configuring the primary indexer cluster to replicate data to a mirrored indexer cluster
On the surface of things, I can't really see any glaringly major differences in either approach.
Any advice on the recommended approach would be appreciated.
DD.
As of Splunk 5.0, the recommended approach is Index Replication.
More info
http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Aboutclusters
Benefits of B: