>I have an existing Splunk server installed onto a Linux server and was wondering if I could use that instead?
Confirmed, you could use also that Linux server.
>Tried installing a Splunk forwarder on the WEC server, however I don't seem to be able to send the events to this remote Splunk server.
It should work with the forwarder both the inputs.conf and outputs.conf are configured correctly.
>Have installed the Logbinder for Splunk on it as an app.
Was it added to the forwarder? In that case in the app's input.conf the following is monitored :
by default in is sending data to index=main
On the forwarder also the destination server should be configured. Is the linux server receiving anything from the forwarder?