I use the basic install on my domain controller and then install forwarder on other machines in the domain. and put my domain controller as the receiver. Will this allow me to set all logs from all system on the network.
I recommend installing Splunk on a different server than your domain controller to prevent Splunk and the DC from competing for the same resources. Install a forwarder on the DC and have all forwarders send their output to the Splunk server.
Either way, yes, you can see the logs from all systems on Splunk.
--- If this reply helps you, an upvote would be appreciated.