<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to modify sourcetype for forwarded windows event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-modify-sourcetype-for-forwarded-windows-event/m-p/480635#M82410</link>
    <description>&lt;P&gt;For some reason, the sourcetype of my forwarded windows events are now set to WinEventType instead of the usual "Windows:xxx". Where do i change the setting for this?  &lt;/P&gt;</description>
    <pubDate>Sun, 19 Apr 2020 14:29:31 GMT</pubDate>
    <dc:creator>minliang</dc:creator>
    <dc:date>2020-04-19T14:29:31Z</dc:date>
    <item>
      <title>How to modify sourcetype for forwarded windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-modify-sourcetype-for-forwarded-windows-event/m-p/480635#M82410</link>
      <description>&lt;P&gt;For some reason, the sourcetype of my forwarded windows events are now set to WinEventType instead of the usual "Windows:xxx". Where do i change the setting for this?  &lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2020 14:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-modify-sourcetype-for-forwarded-windows-event/m-p/480635#M82410</guid>
      <dc:creator>minliang</dc:creator>
      <dc:date>2020-04-19T14:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to modify sourcetype for forwarded windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-modify-sourcetype-for-forwarded-windows-event/m-p/480636#M82411</link>
      <description>&lt;P&gt;Sourcetypes are specified in the inputs.conf files on the forwarders.  Change them at your peril, however.  Your indexers will parse the events based on their sourcetype so changing to an arbitrary type may prevent Splunk from extracting fields.&lt;BR /&gt;
If you're using Splunk's add-on for Windows, know that version 6.0.0 changed the sourcetypes and that source is now used to distinguish security events from other events.  See the app's documentation.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2020 17:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-modify-sourcetype-for-forwarded-windows-event/m-p/480636#M82411</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-19T17:28:53Z</dc:date>
    </item>
  </channel>
</rss>

