Hello, Bit of a novice here. I am in the process of planning to migrate a Splunk universal forwarder from one windows server to another. To my understanding, this is the following process I have come up with: 1. Copy the Splunk home folder from the original forwarder to the newly commissioned server. 2. Download the same version of Splunk. 3. Run the MSI executable, agree to the terms and conditions and open customise settings and select the install location as the same location as the pre-existing configuration. Will the installer then prompt me for any other information, as it already has the configuration? For example will it ask me the deployment server address or the indexor address, or what system account is being used, or to create a splunk local administration account. Will I need to change the host name in any configuration files? If it is not the same as the original server.
... View more