do you mean this file?
"source = /opt/splunk/var/log/splunk/splunkd.log"
I got no entry for the file when I save. But I got the following
2017-11-27 23:12:23,566 ERROR Amp4eEvents - API Error (status 400): {"version":"v1.2.0","metadata":{"links":{"self":"https://api.apjc.amp.cisco.com/v1/event_streams"}},"data":{},"errors":[{"error_code":400,"description":"Bad Request","details":["the server responded with status 404"]}]}
host = localhost.localdomain source = /opt/splunk/var/log/splunk/amp4e_events_input.log sourcetype = amp4e_events_input-2
2017-11-27 23:12:23,566 INFO Amp4eEvents - Received response from ApiService (400)
host = localhost.localdomain source = /opt/splunk/var/log/splunk/amp4e_events_input.log sourcetype = amp4e_events_input-2
2017-11-27 23:12:22,672 INFO Amp4eEvents - ApiService - creating stream with params {'group_guid': [], 'name': u'host', 'event_type': [u'1090519054']}
host = localhost.localdomain source = /opt/splunk/var/log/splunk/amp4e_events_input.log sourcetype = amp4e_events_input-2
... View more