Getting Data In

What configuration settings are used by universal forwarders?

Lowell
Super Champion

Does anyone have a specific listing of what configuration options are honored by the universal forwarder and which ones are not?

I know that parsing and merging happens at the indexer (or intermediate heavy forwarder), but I'm not sure about all the other settings. I read somewhere that the CHARSET has to be set on the universal forwarder, but is that the only one?

I thought a found this in the docs or in a post at one point, but I can't seem to find that information again.

0 Karma
1 Solution

lguinn2
Legend

lguinn2
Legend

Were you thinking of this wiki article?

Where do I configure my Splunk settings?

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...