Installation overview

To deploy the universal forwarder:

  1. Make sure you fulfill the necessary prerequisites. See Universal forwarder prerequisites.
  2. Install the universal forwarder:
  3. To send data to Splunk Enterprise, enable a Splunk Enterprise indexer receiver. See Enable a receiver for Splunk Enterprise.
  4. To send data to Splunk Cloud Platform, you must obtain permissions to use the Splunk Cloud indexer. See Install and configure the Splunk Cloud Platform universal forwarder credentials package.
  5. (Optional) To further modify how data is sent to the indexer, configure the universal forwarder. See Configure the universal forwarder using configuration files.
  6. Start or restart the universal forwarder. See Start or stop the universal forwarder.