I need to forward UF data from windows/Linux Universal Forwarders to a syslog server for a thrid party vendor. I was told that the Heavy Forwarder could split the Splunk stream and forward UF data to a Syslog Server.
Yes, do it like this: https://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/Outputsconf#IndexAndForward_Processor