Splunk® Universal Forwarder

Forwarder Manual

Universal forwarder deployment prerequisites

Before you can deploy the universal forwarder, see the following universal forwarder prerequisites sections:

Decide if you want to use the Splunk deployment server

To personalize how data is sent to the indexer, you edit the universal forwarder's configuration files. Through the deployment server, you can edit multiple universal forwarders at once by manually editing a single file. See About deployment server and forwarder management in the Updating Splunk Enterprise Instances manual.

Computer hardware requirements

The universal forwarder has the following minimum processing, RAM, and disk space requirements:

The hardware requirements for universal forwarders appear in the following table:

Note that to support changes to requirements for App Key Value Store, for Intel x86_64, a Sandy Bridge or higher Core processor is required, with the SSE4.2, AVX, and AES-NI instructions enabled. Ensure your system supports Advanced Vector Extensions (AVX). You cannot upgrade to KV store server version 7.0 unless your system supports AVX and you turn it on in your system's CPU settings.

Recommended Dual-core 1.5GHz+ processor, 1GB+ RAM
Minimum 1.0Ghz processor, 512MB RAM, 5GB of free disk space

Compatible operating systems

For compatible operating systems, see Supported operating systems in the Splunk Enterprise Installation manual.

Last modified on 20 May, 2025
About the universal forwarder   Install a Windows universal forwarder

This documentation applies to the following versions of Splunk® Universal Forwarder: 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.1.8, 9.1.9, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.2.5, 9.2.6, 9.3.0, 9.3.1, 9.3.2, 9.3.3, 9.3.4, 9.4.0, 9.4.1, 9.4.2


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters