Hi raghu0479,
I think that you need an Heavy Forwarder because you have different needs than a Universal Forwarder.
Anyway, you have to:
install a normal full Splunk Enterprise,
go in [Settings -- Forwarding and Receiving]
Configure Forwarding -- Default: Store a local copy of forwarded events? NO
Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port
repeat the last configuration for all your indexers
system will request a splunk restart
Bye.
Giuseppe
... View more