Hello Friend ,
We have a Splunk indexer setup, where All clients send logs directly to the indexer. What we are trying to achieve is to have the indexer to forward the logs to your secure works inspector. Any suggestion will be appreciated.
http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Forwarddatatothird-partysystemsd