which mode does the splunk forwarder support ？ If push or pull mode is all supported， we want to know how to configure the different mode，and the disadvantage and between them？
Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.
Indexer only answers to the connection so the only configurable mode is push.
If there isn't any connection, the UF caches its logs until the connection is again available.
View solution in original post
good for you, see next time!
Ciao and happy splunking.
P.S.: Karma Points are appreciated 😉