Splunk forwarder is currently not compiled for any OS on the IBM Z/architecture. So, any experience will be with workaround for not having a forwarder, 😞
I would recommend filing an Enhancement Request with Splunk for Splunk on Z/OS either natively or under Unix System Services. (USS would obviously be much, much easier)
Ironstream from Syncsort can do what you are looking for. It runs on z/OS and forwards SMF data, Log4j data, SYSLOG and flat files to Splunk. If you would like more information on this product, feel free to contact me.
Splunk forwarder is currently not compiled for any OS on the IBM Z/architecture. So, any experience will be with workaround for not having a forwarder, 😞
I would recommend filing an Enhancement Request with Splunk for Splunk on Z/OS either natively or under Unix System Services. (USS would obviously be much, much easier)