A Splunk forwarder is like a agent in Wazuh Siem. It is a piece of software the runs on a remote machine/client that sends data back to a central server
Unless you have a SSL Cert or know what it is, leave this blank
Select virtual account
Leave all this default
Select the options you want to monitor
Performance monitors with run a lot and fill up your logs
add a user and password
usually you would use the same one for multiple endpoints
If you don't have a deployment server you can skip this
this is your splunk server IP and listening port you set up in server
install
Troubleshooting
if you see this just hit OK some times it works after that other times it will start to roll back. If it has rolled back restart the computer and try again.