At enterprise scale, data onboarding is a disciplined engineering process. The architect defines source types, index strategy, and parsing rules before a single byte enters Splunk. The choice between Universal Forwarder (UF) → Heavy Forwarder (HF) → Indexer and UF → Indexer directly depends on data transformation requirements.
Heavy Forwarders are used when data must be parsed, filtered, or routed before indexing. They can run scripted inputs, apply props.conf transforms, and mask sensitive data (like SSNs via SEDCMD) at ingestion time. This is the architectural boundary for data governance.