Splunk® Universal Forwarder

Forwarder Manual

How to forward data to Splunk Cloud Platform

To forward data to your Splunk Cloud Platform instance, you perform the following procedures:

  1. Download and install the universal forwarder software.
  2. Download the Splunk universal forwarder credentials package.
  3. Install the Splunk universal forwarder credentials package on the universal forwarder machine. See Install and configure the Splunk Cloud Platform universal forwarder credentials package.
  4. To manage forwarders using Splunk Web, configure the universal forwarder to act as a deployment client.
  5. Configure inputs to collect data from the host that the universal forwarder is on. For an overview, see Configure the universal forwarder. For detailed examples of using the CLI to add inputs, see the individual data topics in Getting Data In.


For details on installing Splunk Cloud Platform, see the platform-specific installation instructions in the Splunk Cloud Platform Admin Manual for the type of data you want to forward.

Last modified on 25 March, 2022
Consolidate data from multiple hosts   Advanced configurations for the universal forwarder

This documentation applies to the following versions of Splunk® Universal Forwarder: 8.2.3.1, 8.2.4, 8.2.5, 8.2.6, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 9.4.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters