forwarder

noun

A Splunk instance that forwards data to another Splunk server or a third-party system.

A Splunk server that receives data from a forwarder is called a receiver.

There are three types of forwarders:

In nearly all respects, the universal forwarder represents the best tool for forwarding data to indexers. Its main limitation is that it forwards only unparsed data. Therefore, you cannot use it to route data based on event contents. For that, you must use a heavy forwarder.

Related forms

For more information

In the Distributed Deployment manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time