I installed splunk on 2 servers. One gathers performance data for some applications, and forwards it to another.
Another is configured aa a forwarding receiver, and should collect the data (for displaying etc.)
So, HOW to display the data? What are the steps here?
It would be better if it wasn't in WTF category. I urge sosomeone to delete it 🙂
Aside from the issue with data being forwarded to the incorrect port, which is likely resulting in no data populating your indexes to search against, it isn't clear what you're asking. It seems you have a forwarder and and indexer, and you want to display or search the data on the indexer. This isn't at all specific as basically every function of splunk can fall under this heading.
I hope that some resources will be available as an answer. However, my main problem is that ADMIN that manages my server that receives the data was soooo cool that he forwarded BOTH 8000 and 9997 to 8000 😞