I figured out how to do what I wanted. I have the Universal Forwarder cloning data between two Receivers. One forwards all data on to syslog. The other filters the data and indexes.
Thanks for your response. Telling me that the config should be on the first full Splunk instance helped get me down the correct path.
... View more