To forward data from the UFs to the HFs, put the name or address of the HFs in an outputs.conf file on each UF. See https://docs.splunk.com/Documentation/Forwarder/9.1.0/Forwarder/Configuretheuniversalforwarder for more information. (Replace "Indexer" with "Heavy Forwarder" when reading the instructions.) For sending from HF to Splunk Cloud, there is an app you must download from your Splunk Cloud search head. Go to the "Universal Forwarder" app and click the green download button. Install the downloaded app on the HFs. Despite the name, the app can be used on either UFs or HFs. Note, for better resiliency, consider having multiple HFs with each UF load balancing among them.
... View more