Installation

Universal Forwarder Installation

hectorvp
Communicator

I've a situation where I need to install two Splunk Universal Forwarders over a server.(Not possible to reuse existing UF since it is owned by our vendor, where cannot have control over it using their deployment server)

With Linux I'm following below activities for 2nd UF:

1. Unzip tar package over at different location.

2. Change management ports using web.conf

3. Change server name in splunk-launch.conf

Am I missing any other steps?

Do I need to perform third step??To change service name or no need of it??

If I'm installing two UFs over a windows, would I need to perform this third step their as well??

Is installing two splunk universal forwarders on Linux host officially supported by Splunk, if yes then any reference??

I know it doesn't support for Windows.

 

 If  I use any alternatives to UF (Ex: Rsyslog & WMI), I loose the reliability, so having above approach.

 

 

 

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
Running multiple Splunk instances on the same server is not a supported configuration, but it can be done. Just follow the first two steps you've outlined. There's no need to rename either instance.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust
Running multiple Splunk instances on the same server is not a supported configuration, but it can be done. Just follow the first two steps you've outlined. There's no need to rename either instance.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...