Good morning ,
I have a monitoring for a server(A) and I want to create a new monitoring for a new server (B) by using the same settings (directories) used for the server (A) :
Hi @gcusello
thks for the reply
I actually checked, the Forwarder is not installed, for the download do I have to connect with any username and download the
Hi @yabir,
if you haven't the UF you have to:
Ciao.
Giuseppe
Hi @gcusello
thks for your reply 🙂
I will install the UF setup I found in server A
how long does it take to install is a server reboot necessary ?
is there a license to install too ?
Hi @yabir,
you don't need to reboot server after Forwarder installation.
There isn't any Forwarder's license, they are free: Splunk license is based on the daily log volume you indexed.
Ciao.
Giuseppe
Hi @yabir,
let me understand: you have a Universdal Forwarder installed on ServerA that's sending logs to Splunk Enterprise and now you want to monitor also ServerB; is this your need?
If this is your need, you have to install a Universal Forwarder on ServerB and configure it using the same TAs of ServerA and the same outputs.conf.
In this way you can receive in your Splunk Enterprise logs from both the servers and monitor them.
If instead you already have the logs from server B and you need to modify your alerts, please share them so I can help you.
Ciao.
Giuseppe