Okay here was the answer the Splunk guy gave me regarding the order or ranking of input.conf files:
\etc\system\local\inputs.conf is a sort of master of all. It gets processed last (?) or in any case its settings override all other inputs.conf. Best practice is to have a bare minimum of information there and place all your actual data gathering stanzas (for event logs, perfmons, etc) at \etc\apps\SplunkUniversalForwarder\default\inputs.conf. The deployment server governs that file so pushing changes for all servers would be easier. And obviously if you wanted one-off stanzas for single machines here and there you would add them to \etc\apps\SplunkUniversalForwarder\local\inputs.conf.
The Splunk for Windows TA is just of the Searcher part of your infrastructure; you don't deploy it out to agent/forwarders. Apologies if I got the jargon wrong. I'm a Splunk noob.
... View more