Getting Data In

Can I run multiple Universal Forwarders on Windows Server 2008?

wbfoxii
Communicator

I have a Universal Forwarder looking at a directory holding our proxy logs. New logs are dumped into the directory every 24 hours. Some of the logs are very large and it can take the forwarder 6 to 8 hours to get just one file done. I estimate that it will not complete a full set of new logs in 24 hours, but we might squeak by on the weekend.

Can I set up a second forwarder instance on a Windows Server (2008 R2)? What are the implications?

1 Solution

jbsplunk
Splunk Employee
Splunk Employee

If you try to install via the MSI, it is going to uninstall your previous instance and install another instance. Also, the services will only be bound to one instance. For all practical purposes, it isn't possible without some serious monkeying around with the install.

View solution in original post

Vladimir
Path Finder

You can try just to copy existing installation to another folder, change guid parameter in system/local/server.conf and change values in splunk-launch.conf. But I don't know how to configure a new service in this case, not so familiar with windows stuff but in linux it can be just ./splunk enable boot-start

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

If you try to install via the MSI, it is going to uninstall your previous instance and install another instance. Also, the services will only be bound to one instance. For all practical purposes, it isn't possible without some serious monkeying around with the install.

wbfoxii
Communicator

Thanks for the help, guys. I guess I'll have to look for another creative solution.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...