it is totally unnecessary to install a UF on a SH ->Requirements are determined by policies, so if policy says that it is required to forward all Splunk components to central Splunk for monitoring, then it is necessary. We have a use-case that also requires us to install Splunk UF in all the components: Indexers, Search Heads, Deployment servers. I believe forwarders itself can dual-pipe, however whether it can choose certain index to pipe, I am not very sure. e.g Index 1,2,3 only -pipe to central Splunk All indexes - pipe to local Splunk
... View more