I have 2 remote locations with multiple PCs in both places.
I have installed the forwarder on all devices (Windows PCs). I am collecting event logs (Application and System) from 1 of those locations and I am trying to configure Splunk to also collect event logs from the other, but am obviously getting it wrong somewhere. When I try to configure this in the Add Data menu, I get this error when I try and submit it:
Cannot create another input for the event log "Application". One already exists.
Do I have to configure every store using a different port number or something?
Bit confused so any help appreciated.
Thanks
... View more