universal forwarder

noun

A small-footprint version of a forwarder, a Splunk instance that forwards data to another Splunk server or a third-party system. The universal forwarder is new to version 4.2.

There are three types of forwarders:

  • The universal forwarder is a streamlined, dedicated version of Splunk that contains only the essential components needed to forward data.
  • A heavy forwarder is a full Splunk instance, with some features disabled to achieve a smaller footprint.
  • A light forwarder is also a full Splunk instance, with most features disabled to achieve as small a footprint as possible. Beginning with 4.2, the universal forwarder supersedes the light forwarder for nearly all purposes.

In nearly all respects, the universal forwarder represents the best tool for forwarding data to indexers. Its main limitation is that it forwards only unparsed data. Therefore, you cannot use it to route data based on event contents. For that, you must use a heavy forwarder.

Related terms

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time