Getting Data In

How can I send data from another machine to the machine running splunk Universal forwarder and then have the forwarder send it to the machine running the receiver?

epeeran
Observer

I have a Linux server running the universal forwarder I want another server send data to it and then have the forwarder redirect this data to the splunk receiver server

Tags (1)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

The Universal Forwarder has an inputs.conf just like the indexer.

You then tell the UF via inputs.conf where to look for it or listen for the data coming in.
As Lisa said, you can get it there any way you like.

It will then forward the data to the receiver following the configuration in outputs.conf

If getting the the new data to the current UF is complicated (ie, you'd have to write a script yourself, you don't want to use syslog, etc) consider putting another instance of UF where the data lives.

If you need to use another UF to send the data to your current forwarder you will set up your existing forwarder (the one that will send to the indexer) as an Intermediate Forwarder which will both forward and receive.

NEW UF(sender) -------------->(receiver) EXISTING UF (sender) ---------->INDEXER (receiver)

Since there is no web interface on the Universal Forwarder you have to set it up via the command line (which writes to the inputs.conf) or you can edit inputs.conf and add the stanza like this:
[splunktcp://9997]

The benefit there of course is that Splunk will now keep track of what has been sent and received in the event of a network outage.

All of this is nicely documented, step by step for every scenario. You can start reading here:

http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Introducingtheuniversalforwarder

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

lguinn2
Legend

Getting data to the server running the Universal Forwarder is not part of Splunk. That said, a lot of people use syslog for things like this. Why can't the other machine also have the Universal Forwarder running on it?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...