I'm trying to set up a Splunk instance on linux that can do the following:
receive logs from windows universal forwarders
send some of the logs to our central Splunk server
send all logs to our central log archiving server via syslog protocol
The documentation says that "The syslog output processor is not available for universal or light forwarders." so I guess I'll have to use a Heavy Forwarder in this situation because of the 3rd requirement.