About forwarding and receiving data
You can forward data to Splunk Enterprise, Splunk Light, and Splunk Cloud Platform deployments as well as to systems that don't run the Splunk platform.
The Forwarding Data Manual has more information about forwarding and receiving data with heavy and light forwarders.
Sample forwarding layout
This diagram shows three universal forwarders sending data to a single receiver (an indexer), which then indexes the data and makes it available for searching. This layout is basic, but you can define many forwarding combinations based on your specific environment and network topology.
Forwarders represent a much more robust solution for data forwarding than raw network feeds, with their capabilities for:
- Tagging of metadata (source, source type, and host)
- Configurable buffering
- Data compression
- SSL security
- Use of any available network ports
Universal forwarder system requirements
This documentation applies to the following versions of Splunk® Universal Forwarder: 18.104.22.168, 8.2.4, 8.2.5