The Deployment Server represents 'home' to ONLY those nodes running a forwarder client (who can then 'phone home' to the deployment server). The deployment server should not be running a universal or heavy forwarder because you are running the core enterprise software, wherein, you are directing output (_internal index goodies) directly to the indexer (forwarding and indexing configuration). Both the forwarder and the core installation utilize the splunkd process, so cannot physically both be running on the same node. The deployment server is 'home' and the source of your forwarder inputs sent to your forwarding nodes. I hope this helps.
In Splunk search for the log entry above and take note of the 'source' and 'host' values. This will tell you which node is responsible for generating the event.
... View more