Splunk® Universal Forwarder

Forwarder Manual

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Deploy the universal forwarder

  1. Make sure you have the necessary Universal Forwarder prerequisites.
  2. Install the Universal Forwarder:
  3. To send data to Splunk Enterprise, enable a Splunk Enterprise indexer receiver. See Enable a receiver.
  4. To send data to Splunk Cloud, see Install and configure the Splunk Cloud Platform universal forwarder credentials package. This gives you permissions to use the Splunk Cloud indexer.
  5. Optionally Configure the universal forwarder using configuration files to further modify how data is sent to the indexer.
  6. Start or restart the universal forwarder. See Start or stop the universal forwarder.
Last modified on 11 August, 2022
PREVIOUS
Universal forwarder prerequisites
  NEXT
Install a Windows universal forwarder

This documentation applies to the following versions of Splunk® Universal Forwarder: 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters