There are 2 repositories under splunk-universal-forwarder topic.
Deploy Splunk instances on Windows and Linux in simple, distributed or (multisite) clustered topologies. Demoed by Splunk at .conf2017
This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup a Suricata Port Mirrored Server
writeup about sending Logstash data to Splunk using the HTTP Event Collector
Use this Pack to reduce your Splunk Forwarder log volume.
Ansible Playbook for Splunk Universal Forwarder
Splunk 7 Docker image - https://hub.docker.com/r/giabar/gb-splunk7/
Ansible role to install Splunk Universal Forwarder to Windows/Linux instances by @jesseloudon
Splunk HTTP forwarder class with Metadata
Collection of utilites for interacting with Splunk Enterprise/Universal forwarders releases.
Note: This docker-compose, information built in 2020 and it's built for isolated lab environment, hence some command or information might not up-to-date, however, you may take it as a reference
0.1.6 - BETA : Splunk Windows Universal forwarder lab resources.
Syslog server with Splunk Universal Forwarder baked to allow remote logging from mobile applications.