Set up receiving with the configuration file
You can enable receiving on your Splunk Enterprise instance by configuring inputs.conf in $SPLUNK_HOME/etc/system/local. To configure a universal forwarder as an intermediate forwarder (a forwarder that functions also as a receiver), use this method.
To enable receiving, add a [splunktcp] stanza that specifies the receiving port. In this example, the receiving port is 9997:
From http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Enableareceiver
Set up receiving with the configuration file You can enable receiving on your Splunk Enterprise instance by configuring inputs.conf in $SPLUNK_HOME/etc/system/local. To configure a universal forwarder as an intermediate forwarder (a forwarder that functions also as a receiver), use this method.
To enable receiving, add a [splunktcp] stanza that specifies the receiving port. In this example, the receiving port is 9997:
[splunktcp://9997] disabled = 0