if you haven't the UF you have to:
let me understand: you have a Universdal Forwarder installed on ServerA that's sending logs to Splunk Enterprise and now you want to monitor also ServerB; is this your need?
If this is your need, you have to install a Universal Forwarder on ServerB and configure it using the same TAs of ServerA and the same outputs.conf.
In this way you can receive in your Splunk Enterprise logs from both the servers and monitor them.
If instead you already have the logs from server B and you need to modify your alerts, please share them so I can help you.