I'm was missing something really simple when trying to set up a new datasource, so i put these steps together as i followed the documentation and hope they can help someone out. If I got anything wrong please correct me but this is how i got it working for my needs
step 1: create the index "myindex", i am doing this from inside of the splunk GUI, give it a name and click save
Step 2: stop splunk so i can manually edit/create the conf files needed to perform the desired functions
step 3: create/append $SPLUNK_HOME/etc/apps/search/local/inputs.conf with the following values
got it to work, looks like i was having trouble locating the source after my initial experiments, so it was a simple mistake, but it was hard to find the cause, there was no obvious signs in the logs and no alerts popped up saying there was a problem finding the input file. Probably just a nubie issue but it would be nice to get some more feedback from splunk while trying to create the configurations needed to get the logs in.