Good place to start, Documentation.
Hi blee2,
my approach would be to send this data / events directly to this separate Splunk 6.2 server. If this is not possible for what ever reason; any Splunk instance doing event parsing (Heavy forwarder or Indexer(if no heavy forwarder is in front of it) for example) can do filter and routing. Take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Routeandfilterdatad#Perform_selective_i...
this should give a lot of hints how this could be done. BTW an indexer can be a heavy forwarder at the same time 😉
cheers, MuS