There's a rest endpoint that lists all the files that splunk is monitoring:
For more details as to how exactly use the endpoint is described in the blog post:
If you are post 6.3 you could also use the command:
$SPLUNK_HOME/bin/splunk list inputstatus
still doesn't give me anything remotely close to what i'm looking for, getting anything out of splunk other that the data it's ingesting is like pulling teeth from an angry bear with 3 of his friends with him.