Hi cuppma,
basically you do the reverse version of the docs about Configure Splunk forwarding to use the default certificate. First make sure your indexer is receiving on a non-SSL Port, next you remove the SSL settings from your UF outputs.conf to something like this:
[tcpout:group1]
server=some IP:some Port
Hope this helps to get you started ...
cheers, MuS
... View more