Hi infobrother4,
Verify whether you are getting data from forwarder using the following command.
| tstats count where index=_internal by host
Reference
https://community.splunk.com/t5/Getting-Data-In/Why-are-the-logs-not-getting-forwarded-into-the-splunk-instance/m-p/584654