Its just as the title suggests. If a have a deployment client with an inputs.conf thats already configured as such:
index = web
If I push this inputs.conf to that deployment client from a deployment server?:
index = webLogs
Will the web or webLogs index be populated with events? Or will both be?
The deployment server works at the app level.
And the app has a set of files in directories which could include an inputs.conf.
So if you already had an inputs.conf in /opt/splunk/etc/myapp/local/inputs.conf and the server.conf is going to deploy myapp to the client it will overwrite it.
View solution in original post
Exactly. And if they are not in the same app / folder, then Splunk determines the precedence based on the location of each inputs.conf: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles