Splunk® Universal Forwarder

Forwarder Manual

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Deploy the universal forwarder

To deploy the universal forwarder, follow these high-level steps:

  1. Make sure you fulfill the necessary prerequisites. See Universal forwarder prerequisites.
  2. Install the universal forwarder:
  3. To send data to Splunk Enterprise, enable a Splunk Enterprise indexer receiver. See Enable a receiver for Splunk Enterprise.
  4. To send data to Splunk Cloud Platform, you must obtain permissions to use the Splunk Cloud indexer. See Install and configure the Splunk Cloud Platform universal forwarder credentials package.
  5. (Optional) To further modify how data is sent to the indexer, configure the universal forwarder. See Configure the universal forwarder using configuration files.
  6. Start or restart the universal forwarder. See Start or stop the universal forwarder.
Last modified on 01 April, 2024
PREVIOUS
Universal forwarder deployment prerequisites
  NEXT
Install a Windows universal forwarder

This documentation applies to the following versions of Splunk® Universal Forwarder: 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.2.0, 9.2.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters