So, the SplunkUniversalForwarder app holds the configurations that normally define default inputs and settings for a Universal Forwarder. It can be utilized like any other app, though, as you can see here. It doesn't mean that the UF was installed via an app, only that the app named SplunkUniversalForwarder is where the previous person stored their custom configurations. They may also have put their outputs.conf configuration in there as well, so to add the new indexer, you would just need to modify the outputs.conf to include it.
... View more