I'm writing my own modular input, using the docs, Python examples, SNMP TA, and the Splunk Add-on for ServiceNow as a learning base.
Looking at the Splunk Add-on for ServiceNow, there are a kajillion .py files in bin/. How does Splunk know that snow.py is the main for the modular input, instead of one of the other scripts?
you can go to /README/inputs.conf.spec. There would be an entry such as:
[snow://]
snow.py would be the main starting point.