Where is the forwarder configured to send the data (outputs.conf)?
You don't ever "need all those logs on your desktop"; they will go into an indexer which will do your bidding when you access it's data through your browser ("on your desktop").
The indexer will not "pass the logs"; the indexer is the final destination for them.
As far as "parsing", I assume you already have a "rex" command working so you can convert this to an automatic field extraction with props.conf:
http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
... View more