4 Answers

Forwarders are the one which will securely collects the logs from various log sources and hand over to Spunk for Indexing and further procedures.

The types of forwarders are Universal forwarders and Heavy forwarders
Splunk forwarder is an agent to collect the logs from the data sources like servers, critical end user machines, db etc .

There are two types of forwarders in splunk

Universal forwarder and Heavy forwarder.

Universal forwarder will collect logs and forward it to Heavy forwarder (optional) or  directly forward it to the indexer for storage.
Forwarders are the one which works as a agent and push all the logs from all data sources to indexers

two types

1)Universal forwarder -installed in data source and push logs to indexer or heavy forwarder(optional)

2)Heavy forwarder(optional)-collect logs from various universal forwarder and push to indexer
Forwarders are mainly used to collect logs from different log sources

Types of forwarders:

Universal, heavy forwarders

