Universal Forwarders (UF) are lightweight agents that collect and forward raw data. They do NOT parse data. Heavy Forwarders (HF) are full Splunk instances that parse, filter, and route data before forwarding.
Use UFs for simple log collection. Use HFs when you need to mask sensitive data (like credit card numbers) or route specific events to different indexes before they reach the indexers.