You've chosen the wrong type of TCP input on forward1. You've got a raw TCP input there on port 9997, but what you really want is a receiving port that is used specifically for receiving cooked data from other Splunk instances - in the manager, it's listed under the "Forwarding and receiving" section" rather than the "Data inputs" section.
More info on setting up receiving, and generally deploying Splunk in a distributed architecture, can be found here for instance:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Setupforwardingandreceiving
http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Enableareceiver
... View more