With a single Splunk instance, an outage-perhaps for an operating system upgrade-will cause events to queue on the Splunk forwarder instances. If there are multiple indexers, the forwarders will continue to send events to the remaining indexers.
Let's walk through a simplified scenario. Given these four machines, with the forwarders configured to load balance their output across two indexers, as shown in the following diagram:
While everything is running, half of the events from each forwarder data will be sent to each indexer. If one indexer is down, we are left with only one indexer as shown in the diagram: ...