the universal forwarder was installed on a server to send info to splunk. We don't see any traffic coming from the forwarder. What's the best way to see the config for the forwarder.
I'm not sure what you mean by "the universal forwarder was installed" but a good first step would be to check this out :
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving