My question is - which inputs.conf file? The data is coming in to my Search Head server and there are a bunch of apps installed there, each with their own inputs.conf file. Which one controls the TCP Data Inputs?
Any app can contain inputs.conf and set TCP attributes. I recommend creating a custom app (org_tcpinputs) for the settings. Before restarting Splunk to apply the changes, run btool to verify the settings are as you expect. That's to avoid conflicts with another app.
--- If this reply helps you, an upvote would be appreciated.