This is done in $SPLUNK_HOME/apps/Splunk_TA_nix/local/inputs.confand this is in "Splunk Add-on for Unix and Linux" in version 7.0.0 but I think that actually doesn't matter.
I found that the change comes from $SPLUNK_HOME/apps/Splunk_Security_Essentials/appserver/static/data_source.js (in line 1106 for v3.0.3). All other "source"-values for "monitor"-stanzas stay correct, i.e left unchanged at their default. This "secure"-source really should also stay at its original value, i.e. source=/var/log/secure.