Hi,
splunk maintains its default settings in $SPLUNK_HOME/etc/system/default path...
If you want to make any changes on default properties, then you can create inputs.conf or index.conf etc conf files under /etc/system/local/ direcotry....
use same stanza's in *.conf files. with different values... Hope It will helpful
Thanks,
Srinivas
... View more