Hi,
Yes all your points are correct. The UF is just a lightweight agent that collects data.
It is a different installer. Take a look at the docs:
http://www.splunk.com/en_us/download/universal-forwarder.html
http://docs.splunk.com/Splexicon:Universalforwarder
http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Universalforwarderdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Aboutforwardingandreceivingdata
https://answers.splunk.com/answers/58888/what-are-the-ports-that-i-need-to-open.html
Hope that helps.
Thanks,
J
... View more