Does Splunk Universal Forwarder forward audit event logs to Splunk _audit index?
I can see Splunk HF's are forwarding audit events, but couldn't find which app has inputs.conf which enable reading audit logs and forward to _audit index.
May I know which app consists inputs to read and send data to _audit index in Splunk?
You would see default/outputs.conf on the SplunkForwarder app with
forwardedindex.x.whitelist= (_audit | _introspection | _telemetry)
This would forward all the _* logs to index layer.