Splunk for Change Management
From Splunk Wiki
to configure the inputs for this application under 3.3.2 use: $SPLUNK_HOME/etc/apps/change_management/default/inputs.conf
here's an example of inputs.conf:
[fschange:/usr/local/etc] pollPeriod = 60 disabled = false
don't forget to restart the splunk server after modifying inputs.conf.