Hello,
Please could anyone advice me, how I can get two instance of Universal forwarders run from one Linux Box? I am aware that we can use a single forwarder to forward to multiple indexes; however in my case I am not allowed to touch or alter the existing forwarder as it is mission critical; however I am tasked to do a POC to confirm the forwarding will work to a sandbox machine where we are testing some new Splunk server configurations.
Please can someone help me resolve this problem ?
Thanks.
It's pretty simple. All you have to do is unzip or uninstall to a different location. When you start up the first time, it will also ask you to change ports (since the default one will be occupied). Pick a new port number (it doesn't matter what). That's all.