Hey there. Check Splunk's _internal index for any nuggets of info on this issue. This is assuming that the internal logs are being forwarded. If not look at the splunkd.log file on the host that has the input configured.
Splunk btool command may be of use to ensure that this config is even being read or being over ridden somehow. If you are editing the inputs.conf manually make sure that splunkd can read the inputs.conf file.