Splunk's behavior is controlled by .conf files located under $SPLUNK_HOME/etc/. The directory structure follows a precedence hierarchy.
System-level configs live in system/default/ (never edit these!) and system/local/ (for your overrides). App-level configs live in apps/<app-name>/default/ and apps/<app-name>/local/.
Splunk merges these layers together, with local/ always winning over default/, and app-level winning over system-level for the current app context.