Splunk® Universal Forwarder

Forwarder Manual

Download manual as PDF

Download topic as PDF

How to forward data to Splunk Cloud

To forward data to your Splunk Cloud instance, you perform the following procedures:

  1. Download and install the universal forwarder software.
  2. Download the Splunk universal forwarder credentials package.
  3. Install the Splunk universal forwarder credentials package on the universal forwarder machine.
  4. To manage forwarders using Splunk Web, configure the universal forwarder to act as a deployment client.
  5. Configure inputs to collect data from the host that the universal forwarder is on. For an overview, see Configure the universal forwarder. For detailed examples of using the CLI to add inputs, see the individual data topics in Getting Data In.

For details on installing Splunk Cloud, see the platform-specific installation instructions in the Splunk Cloud User Manual for the operating system from which you want to forward data.

How to forward data to Splunk Light Cloud
How to forward data to Splunk Enterprise

This documentation applies to the following versions of Splunk® Universal Forwarder: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters