If you set up your deployment server as a forwarder, by adding an outputs.conf file, you can send its Splunk logs to your indexer. Splunk automatically monitors its internal logs, so your deployment-related logs should be sent automatically. The following example assumes that the indexer is named yourhost.yourcompany.com and that it is listening for input on port 9997.
outputs.conf
[tcpout:group1]
server=yourhost.yourcompany.com:9997
If this doesn't work like you expect, make sure that your deployment server has an inputs.conf that contains something like this:
[monitor://$SPLUNK_HOME/var/log/splunk]
_TCP_ROUTING = *
index = _internal
Here is a good item in the documentation: What Splunk logs about itself
... View more