I hope that some resources will be available as an answer. However, my main problem is that ADMIN that manages my server that receives the data was soooo cool that he forwarded BOTH 8000 and 9997 to 8000 😞
Aside from the issue with data being forwarded to the incorrect port, which is likely resulting in no data populating your indexes to search against, it isn't clear what you're asking. It seems you have a forwarder and and indexer, and you want to display or search the data on the indexer. This isn't at all specific as basically every function of splunk can fall under this heading.