Getting Data In

Can i run two splunk universal forwarders on a single windows server?

kollampalli
Engager

Hi,

I have one splunkforwader installed on my windows server which is configured by some other user, Now I want to have my own splunk forwarder to be set up without affecting any configuration files and forwarding of the 1st splunk forwarder, Is it possible? I have gone through this link http://wiki.splunk.com/Community:Run_multiple_Splunks_on_one_machine regarding the same but the steps explained on this link has some deletion of files and directories from the 1st forwarder and then we have to copy that instance to a different directory, i'm not sure if that will affect the configuration of the 1st forwarder.

Please can anyone advice?

Thanks in advance 🙂

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

The simple answer is no, Windows allows only 1 services.

The best alternative is to install 2 different services :
1 - an universal forwarder
2- a regular splunk with the "light weight forwarder" enabled.

But I still wonder why you would want to do such a thing, you will finish with duplicated data, extra license consumption, and a pain to maintain ?

0 Karma

kollampalli
Engager

I think i was not very clear, Actually we have a pre-configured forwarder running on our windows server by other user, it is configured in such a way that it can only forward the logs which are registered on it, Also it has many features disabled like we can't install splunk_TA windows app on it to monitor CPU,Disk,Network Usage on the same server,I came across an option to install multiple forwarders from the link which i shared but i am not sure if deleting the files & directories from the existing forwarder and making an new instance out of it will affect the configuration of 1st instance

0 Karma

aholzer
Motivator

I'm with yannK. You probably should simply look into creating separate apps that you can call your own, rather than trying to make a new install work.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...