Currently Splunk Sandbox DOES support forwarding data via Universal Forwarders.
On the other hand, raw UDP SYSLOG forwarding directly to the Sandbox (without a Universal Forwarder) is not supported. This is done for good reasons. To forward SYSLOG data from a host, a Universal Forwarder can be installed and configured to monitor and push local SYSLOG to the Sandbox.
... View more