I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...
I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.
good luck...
... View more