I thought of another thing to check...
If the user running splunk is not root... what permissions does the user have?
I ran into a scenario where I deployed my forwarders as root, but, my SH, IDX, and HF's as splunk.... so, while all of the other boxes were reporting their/var/log/*... my splunk infrastructure was not sending logs due to permissions and not just inputs.conf sequencing.
Sorry to muddy the waters... but, it's a variable.
... View more