What is the point of the heavy forwarder outlined in step 4 of the docs?
- Next, install a full Splunk instance that has an outbound connection to the Internet. Note: This server should be separate from the central Splunk App for Microsoft Exchange instance and any Exchange servers which also run universal forwarders.
Is that heavy forwarder doing anything that can't be done at the indexer?