Setup the Linux server as a forwarder, and configure the outputs to point to the Windows Splunk instance.
Output.conf on Linux Splunk instance:
[tcpout:windows_indexer]
server=<windows_host/IP>:9997
Also configure the Windows Splunk instance with a Splunk TCP input:
Inputs.conf on Windows Splunk index:
[splunktcp://9997]
Don't forget about firewall on the Windows host, and also any indexes required for apps on the Linux instance will need to be installed on the Windows. Basically, TAs go on Linux, app goes on Windows (if you don't plan on using the Linux front end).
... View more