We are using the Splunk Add-on for Microsoft Windows to get Windows Event sourcetypes that we're forwarding from Universal Forwarders. We're managing our UF's with a deployment server. I would like to have different settings for inputs.conf with the Splunk_TA_windows add-on for different UF's, but would still like to maintain all types of configuration from the deployment server.
Am I correct in thinking I can duplicate the app on my deployment server to apply to other types of UF's as "Splunk_TA_windows2"? Is there a better way to leverage the same app from a deployment server with different configurations for server classes?
It's worked out for our needs. We haven't upgraded the app yet, but I don't imagine much would change for the inputs between versions. And we don't really touch the apps often, only if we need to start or stop ingesting a new event id or event log, etc. And in some cases it affects all of the copies and some cases just one particular copy.