We have two collector server collecting events from all windows based servers(400 of them). Windows servers are currently set to send locally generated events to the both collectors(duplicate).
we are wanting to install splunk agents in both servers and forward all collected events to the central splunk server
Now we have following questions
1) How does license restriction will work e.g. will we have to buy double the size licenses?
2) While indexing will duplicate event logs be indexed?
Thanks in advance.
Yes to both.
Thank you for the quick answer.