First you should read and understand this: http://docs.splunk.com/Documentation/Splunk/6.1.2/Admin/Configurationfiledirectories - the surrounding pages don't hurt either.
Where that UDP input is depends on where you've configured it to be. It'll certainly be in some local directory, because default isn't meant to be changed by the end user.
You could check through all of them, or run this:
$SPLUNK_HOME/bin/splunk cmd btool --debug inputs list udp
... View more