Universal Forwarders require an inputs.conf file to tell them which log to send to the indexer. That file can be defined locally or come from a deployment server. You told your UF to get it from a deployment server, but did you set up a DS? You didn't mention it. On the search head (the instance listening on port 8000), go to Forwarder Management to set up the deployment server. See https://docs.splunk.com/Documentation/Splunk/8.1.0/Updating/Deploymentserverarchitecture and https://docs.splunk.com/Documentation/Splunk/8.1.0/Updating/Planadeployment
... View more