Hi rajuljain19900526,
assuming you installed the full Splunk version on both (not only the universal forwarder on your forwarding server2), then this will be the default behavior for Splunk on server2. If you want Splunk on server2 to locally index and forward the events to server1 read the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding
Index all the data before forwarding it. To do this, just enable the indexAndForward attribute in outputs.conf.
Or goto Settings » Forwarding and receiving » Forwarding defaults in the UI and select
Store a local copy of forwarded events?
Hope this helps ...
cheers, MuS
... View more