U
universal forwarder
A type of forwarder , which is a Splunk Enterprise instance that sends data to another Splunk Enterprise instance or to a third-party system. The universal forwarder is a dedicated, streamlined version of Splunk Enterprise that contains only the essential components needed to forward data. The universal forwarder does not support python and does not expose a UI. In most situations, the universal forwarder is the best way to forward data to indexers. Its main limitation is that it forwards unparsed data, except in certain cases, such as structured data . You must use a heavy forwarder to route event-based data. In the Universal Forwarder manual:
Related Products: Platform
upstream
adjective, noun In the context of open source software, upstream refers to the original source or precursor projects from which distributions or downstream projects are derived. For example, the Linux kernel is upstream to all existing Linux distributions. The OpenTelemetry Collector project is upstream to the Splunk Distribution of OpenTelemetry Collector, meaning that the former is the precursor and the latter receives updates and expands on the code that comes from upstream.
Related Products: Platform
Related Terms: distribution
urgency
The importance of a notable event , such as low, medium, high, or critical. Splunk Enterprise Security calculates urgency based on the severity of the correlation search and the priority of the asset or identity involved in the event.
Related Products: Platform, Enterprise Security
user authentication
The process that identifies users in order to allow or restrict access to the Splunk platform and determine their levels of permissions. The Splunk platform supports the following types of user authentication: In Securing Splunk platform :
Related Products: Platform