Is splunk capable of pulling multiple log files from different servers without installing the universal forwarder on the machines?
You can monitor files remotely by exposing the logs in a file share, then mount and monitor it on a server where you have a Splunk forwarder or indexer installed. Most filesharing protocols should work (eg. SMB/CIFS, NFS, SSHFS, ...)
ziegfried is correct, but we generally would recommened installing the universal forwarder for best experience.