Splunk Universal Forwarder

Configuring Splunk Universal Forwarder to send data to LOGIQ

Raw mode ( not cooked )

Splunk universal forwarders support forwarding raw data as it is collected as well in Splunk's proprietary protocol S2S. LOGIQ.AI can directly ingest from Splunk UF in raw mode that does not use proprietary S2S protocol.
Splunk Universal Forwarder can be configured to send raw TCP data to LOGIQ. To enable forwarding to LOGIQ edit $SPLUNK_HOME/etc/system/local/outputs.conf file and enable TCP forwarding.
disabled = false
defaultGroup = logiq
server = <logiq_instance>:<raw port>
negotiateProtocolLevel = 0