$SPLUNK_HOME/etc/apps/search/local has all of my custom defined data inputs. This one in particular is
[udp://515] and lists:
[udp://515] index = indexA source = sourceA sourcetype = sourcetypeA connection_host = dns
That being said, should this inputs.conf be located elsewhere, such as in
$SPLUNK_HOME/etc/system/local where the props.conf and transforms.conf are located, or should I move props and transforms to be with this inputs? I wouldn't think it matters honestly.
If I run
btool as you suggested it pulls props from
$SPLUNK_HOME/etc/system/default, but the transforms it refers to is from
Do you have a sample event (sanatized) that you can share? all of these things should be working. You can keep them in system/local, that's fine for now.
Join us on IRC, #splunk on efnet.org, and we can discuss real-time what and how.