Selecting Windows IIS logs (C:\inetpub\logs\LogFiles\W3SVC) as event source during the installation of Universal Forwarder (splunkforwarder-6.5.1-f74036626f0c-x64-release.msi) resulted in data/events being forwarded to the Index (as expected), but I cannot find any entries in (C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf) to show for this selection I made during the installation.
Where are the config details stored when specifying during the UF Installation?
Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...
As mentioned above, btool is your best bet for finding where a setting originates. Be sure to add the debug option so you can find the path:
splunk btool inputs list --debug > somefilename.txt