Universal Forwarders (UF) are lightweight agents that collect and forward data. They use minimal resources and can't parse or index data locally.
Heavy Forwarders (HF) are full Splunk instances that can parse, filter, and route data before forwarding. Use them when you need pre-processing at the source.
Forwarders connect to indexers using outputs.conf. Load balancing across multiple indexers is configured with autoLB settings.
[tcpout]
defaultGroup = my_indexers
[tcpout:my_indexers]
server = idx1:9997, idx2:9997, idx3:9997
autoLB = true