I have a forwarder pushing java log data to an indexer. The inputs on the index was set to log4j. However in the basic summary screen, the sourcetype is shown as server.
Why is this?
Is there anyway to rename this sourcetype, or creating based on an existing one with a different name?
You can specify the sourcetype in a few places.
On the forwarder, in inputs.conf:
[monitor://path to log file] sourcetype=log4j
On the indexer, in props.conf:
[source::full path to log file] sourcetype=log4j
Your description is a bit confusing. You say that "the inputs on the index was set to log4j", do you mean that the inputs.conf file on the forwarder, within the stanza collecting this file, has a line that says "sourcetype=log4j"?