I'm in the very same boat. I can see the traffic coming in on port 9997 using tcpdump, but I cannot see the forwarders at all on the Add Data panel. I'm very new to Splunk (just this week). I see this post was back in February - did you ever get it to work?
... View more