I'm not sure what you are trying to do on a forwarder?
You should not install it on the forwarder but in etc/apps directory.
To receive administrative events from MongoDB hosts, enable a mongo_admin data input under Settings > Data Inputs > MongoDB Admin
MongoDB Collection Stats
To fetch collection statistics from MongoDB hosts, enable a mongo_collstats data input under Settings > Data Inputs > MongoDB Collection Stats
MongoDB Database Stats
To fetch database statistics from MongoDB hosts, enable a mongo_db data input under Settings > Data Inputs > MongoDB Database Stats
There are 3 ways to get MongoDB logs into Splunk:
set up a file monitor on the Splunk Universal Forwarder to tail mongod.log on all MongoDB hosts
configure mongod to send logs to Splunk via syslog
configure the MongoDB Monitoring app to collect logs via the MongoDB Client API by adding a data input under Settings > Data Inputs > MongoDB Logs
The MongoDB Monitoring app applies field extractions to the mongod sourcetype. By default the dashboards expect MongoDB logs to reside in the mongodb index with sourcetype mongod. You can change this by modifying the mongo_index and mongo_sourcetype macros under Settings > Advanced search > Search macros.