On server B, can you show me:
- $SPLUNK_HOME/etc/system/local/inputs.conf
- $SPLUNK_HOME/etc/system/local/outputs.conf
- the output of 'splunk list monitor'
On server A, can you show me:
- $SPLUNK_HOME/etc/system/local/inputs.conf
Does the alert log have a header or any binary data in it? I don't believe it does, but it doesn't hurt to check.