Getting Data In

How does splunk indexing works when two or more windows based collector sending same Event logs?

AKG
Path Finder

Hi

We have two collector server collecting events from all windows based servers(400 of them). Windows servers are currently set to send locally generated events to the both collectors(duplicate).

we are wanting to install splunk agents in both servers and forward all collected events to the central splunk server

Now we have following questions

1) How does license restriction will work e.g. will we have to buy double the size licenses?
2) While indexing will duplicate event logs be indexed?

Thanks in advance.

Tags (1)
0 Karma

AKG
Path Finder

Thank you for the quick answer.

0 Karma

sowings
Splunk Employee
Splunk Employee

Yes to both.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...