We use the Splunk metric store that was introduced in the early version of 7.0, any Splunk version starting 7.0.x will comply with the requirements.

Splunk Universal Forwarder

A Splunk Universal Forwarder instance is deployed on each component to achieve monitoring and indexing of the application events.

In most cases, you will use a Splunk Deployment Server to manage configuration of the Universal Forwarder.