We have multiple HF's and one DS in our environment. We want to monitor the underlying Linux operating System for which our HFs and DS run's on by forwarding it's OS events to Splunk indexers.
Is the process for doing this the same as any other server? Install a UF and enter the usual config?
Splunk can monitor its own server without a UF. Use the same TA to collect the information and forward it to the indexers.