is it advised to have both a cribl agent and a splunk universal forwarder installed on a host?
It is very much dependent on the use case. However, in most cases the goal is to reduce the number of agents. So we see people moving away from Splunk UF and into Cribl Edge agent
It really depends on how your splunk UF is configured to ingest things in, would strongly suggest testing a bit before you cut over.