To build on this, while "best" is an "it depends" provoking question, I want to share with you that when I first started playing with Splunk, I also started with the classic full Splunk Enterprise install. Only after learning more and understanding the differences in forwarder types was I able to make a more informed choice to switch to the Universal Forwarder.
So, there's nothing "wrong" with what you're doing. I suggest, as you get more comfortable, read some of this material to learn more about the choices you are able to make, should you choose to make them.
Also, take a peek at the system requirements for Splunk on VMs. Those VMs are probably fine to play with but there's things to consider and min specs to get to when it's time to party in production.