Getting Data In
Highlighted

How does splunk indexing works when two or more windows based collector sending same Event logs?

Path Finder

Hi

We have two collector server collecting events from all windows based servers(400 of them). Windows servers are currently set to send locally generated events to the both collectors(duplicate).

we are wanting to install splunk agents in both servers and forward all collected events to the central splunk server

Now we have following questions

1) How does license restriction will work e.g. will we have to buy double the size licenses?
2) While indexing will duplicate event logs be indexed?

Thanks in advance.

Tags (1)
0 Karma
Highlighted

Re: How does splunk indexing works when two or more windows based collector sending same Event logs?

Splunk Employee
Splunk Employee

Yes to both.

0 Karma
Highlighted

Re: How does splunk indexing works when two or more windows based collector sending same Event logs?

Path Finder

Thank you for the quick answer.

0 Karma